Aggregates CVE and security vulnerability intelligence across all JetBrains-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk xxe and vendor risk open redirect and related problems; some flaws may lead to vendor impact session compromise, affecting vendor surface production workloads scenarios.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-61492 | In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible | [email protected] | 3.5 | 0.39% | 2026-07-10 | 2026-07-10 |
| CVE-2026-59796 | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks | [email protected] | 8.1 | 0.25% | 2026-07-10 | 2026-07-14 |
| CVE-2026-59795 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible | [email protected] | 8.1 | 0.20% | 2026-07-10 | 2026-07-13 |
| CVE-2026-59794 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data | [email protected] | 7.3 | 0.15% | 2026-07-10 | 2026-07-10 |
| CVE-2026-59793 | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | [email protected] | 8.8 | 0.34% | 2026-07-10 | 2026-07-14 |
| CVE-2026-59792 | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible | [email protected] | 9.6 | 0.42% | 2026-07-10 | 2026-07-14 |
| CVE-2026-59791 | In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible | [email protected] | 3.5 | 0.14% | 2026-07-10 | 2026-07-10 |
| CVE-2026-57926 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack | [email protected] | 2.6 | 0.18% | 2026-06-26 | 2026-06-27 |
| CVE-2026-57925 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags | [email protected] | 4.3 | 0.17% | 2026-06-26 | 2026-06-27 |
| CVE-2026-57924 | In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details | [email protected] | 4.3 | 0.17% | 2026-06-26 | 2026-06-27 |
| CVE-2026-57923 | In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings | [email protected] | 5.3 | 0.16% | 2026-06-26 | 2026-06-27 |
| CVE-2026-57922 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible | [email protected] | 3.1 | 0.14% | 2026-06-26 | 2026-06-27 |
| CVE-2026-57921 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint | [email protected] | 4.3 | 0.16% | 2026-06-26 | 2026-06-27 |
| CVE-2026-53914 | In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata | [email protected] | 6.7 | 0.20% | 2026-06-26 | 2026-06-27 |
| CVE-2026-56142 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible | [email protected] | 9.9 | 0.41% | 2026-06-19 | 2026-06-26 |
| CVE-2026-56141 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible | [email protected] | 9.8 | 0.36% | 2026-06-19 | 2026-06-26 |
| CVE-2026-53915 | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration | [email protected] | 7.1 | 0.25% | 2026-06-19 | 2026-06-26 |
| CVE-2026-50242 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | [email protected] | 10.0 | 0.44% | 2026-06-19 | 2026-06-26 |
| CVE-2026-49386 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas | [email protected] | 6.5 | 0.25% | 2026-05-29 | 2026-06-17 |
| CVE-2026-49385 | In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts | [email protected] | 6.5 | 0.21% | 2026-05-29 | 2026-06-17 |