
PEACH
Un framework di isolamento del tenant
CVE-2026-103496 is an Insecure Direct Object Reference (IDOR) vulnerability in JetBrains YouTrack's inbox threads feature that allows authenticated users to read other users' notifications by manipulating object references. It affects all YouTrack versions before 2026.2.19422 and was disclosed on October 1, 2026. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium), assigned by JetBrains (GitHub Advisory, JetBrains).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), where the application fails to validate that the requesting user is authorized to access the inbox thread object being referenced. An authenticated attacker can manipulate the object identifier (e.g., a thread ID or notification ID) in API requests to retrieve inbox notifications belonging to other users, bypassing per-user authorization checks. The attack requires only low privileges (a valid account) and no user interaction, and is exploitable remotely over the network with low complexity (GitHub Advisory, JetBrains).
Successful exploitation results in unauthorized read access to other users' YouTrack inbox notifications, constituting a confidentiality breach. There is also a low integrity impact, as the ability to interact with or manipulate another user's inbox threads may allow limited unauthorized modifications. Availability is not affected. The scope of impact is limited to the YouTrack application itself, with no evidence of lateral movement potential beyond the platform (GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable per SSVC assessment, as it requires an authenticated session (GitHub Advisory).
JetBrains has released a fix in YouTrack version 2026.2.19422. All users should upgrade to this version or later as the primary remediation. No specific configuration-based workaround has been published; until patching is possible, administrators should review access logs for anomalous inbox API activity and consider restricting YouTrack access to trusted networks or VPN (JetBrains, GitHub Advisory).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."