
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-103496 is an Insecure Direct Object Reference (IDOR) vulnerability in JetBrains YouTrack's inbox threads feature that allows authenticated users to read other users' notifications by manipulating object references. It affects all YouTrack versions before 2026.2.19422 and was disclosed on October 1, 2026. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium), assigned by JetBrains (GitHub Advisory, JetBrains).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), where the application fails to validate that the requesting user is authorized to access the inbox thread object being referenced. An authenticated attacker can manipulate the object identifier (e.g., a thread ID or notification ID) in API requests to retrieve inbox notifications belonging to other users, bypassing per-user authorization checks. The attack requires only low privileges (a valid account) and no user interaction, and is exploitable remotely over the network with low complexity (GitHub Advisory, JetBrains).
Successful exploitation results in unauthorized read access to other users' YouTrack inbox notifications, constituting a confidentiality breach. There is also a low integrity impact, as the ability to interact with or manipulate another user's inbox threads may allow limited unauthorized modifications. Availability is not affected. The scope of impact is limited to the YouTrack application itself, with no evidence of lateral movement potential beyond the platform (GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable per SSVC assessment, as it requires an authenticated session (GitHub Advisory).
JetBrains has released a fix in YouTrack version 2026.2.19422. All users should upgrade to this version or later as the primary remediation. No specific configuration-based workaround has been published; until patching is possible, administrators should review access logs for anomalous inbox API activity and consider restricting YouTrack access to trusted networks or VPN (JetBrains, GitHub Advisory).
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."