Vulnerability DatabaseCVE-2026-103496

CVE-2026-103496: 
YouTrack vulnerability analysis and mitigation

Overview

CVE-2026-103496 is an Insecure Direct Object Reference (IDOR) vulnerability in JetBrains YouTrack's inbox threads feature that allows authenticated users to read other users' notifications by manipulating object references. It affects all YouTrack versions before 2026.2.19422 and was disclosed on October 1, 2026. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium), assigned by JetBrains (GitHub Advisory, JetBrains).

Technical details

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), where the application fails to validate that the requesting user is authorized to access the inbox thread object being referenced. An authenticated attacker can manipulate the object identifier (e.g., a thread ID or notification ID) in API requests to retrieve inbox notifications belonging to other users, bypassing per-user authorization checks. The attack requires only low privileges (a valid account) and no user interaction, and is exploitable remotely over the network with low complexity (GitHub Advisory, JetBrains).

Impact

Successful exploitation results in unauthorized read access to other users' YouTrack inbox notifications, constituting a confidentiality breach. There is also a low integrity impact, as the ability to interact with or manipulate another user's inbox threads may allow limited unauthorized modifications. Availability is not affected. The scope of impact is limited to the YouTrack application itself, with no evidence of lateral movement potential beyond the platform (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable per SSVC assessment, as it requires an authenticated session (GitHub Advisory).

Exploitation steps

  1. Obtain authenticated access: Log in to a vulnerable JetBrains YouTrack instance (any version before 2026.2.19422) with a valid low-privileged user account.
  2. Identify inbox thread endpoint: Navigate to or intercept API requests related to the inbox/notifications feature (e.g., requests to the inbox threads API endpoint) using a web proxy such as Burp Suite.
  3. Enumerate object identifiers: Observe the thread or notification IDs used in API requests for the attacker's own inbox. Note the format and range of these identifiers.
  4. Manipulate object references: Modify the thread or notification ID parameter in the API request to reference IDs belonging to other users (e.g., incrementing or fuzzing numeric IDs).
  5. Read other users' notifications: If the server returns notification data for the manipulated ID without enforcing ownership checks, the attacker can read inbox notifications belonging to other YouTrack users (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or high-volume API requests to YouTrack inbox/thread endpoints with sequentially or randomly varying thread/notification IDs from a single authenticated user session.
  • Logs: YouTrack access logs showing a single user account accessing inbox thread IDs that do not correspond to their own notifications; repeated 200 OK responses to inbox API calls with IDs outside the user's expected range.
  • Behavioral: A user account making significantly more inbox/notification API requests than typical usage patterns would suggest, particularly across a wide range of object IDs.

Mitigation and workarounds

JetBrains has released a fix in YouTrack version 2026.2.19422. All users should upgrade to this version or later as the primary remediation. No specific configuration-based workaround has been published; until patching is possible, administrators should review access logs for anomalous inbox API activity and consider restricting YouTrack access to trusted networks or VPN (JetBrains, GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related YouTrack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103493HIGH8.1
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103494MEDIUM6.6
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103495MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management