
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-103496 is an Insecure Direct Object Reference (IDOR) vulnerability in JetBrains YouTrack's inbox threads feature that allows authenticated users to read other users' notifications by manipulating object references. It affects all YouTrack versions before 2026.2.19422 and was disclosed on October 1, 2026. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium), assigned by JetBrains (GitHub Advisory, JetBrains).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), where the application fails to validate that the requesting user is authorized to access the inbox thread object being referenced. An authenticated attacker can manipulate the object identifier (e.g., a thread ID or notification ID) in API requests to retrieve inbox notifications belonging to other users, bypassing per-user authorization checks. The attack requires only low privileges (a valid account) and no user interaction, and is exploitable remotely over the network with low complexity (GitHub Advisory, JetBrains).
Successful exploitation results in unauthorized read access to other users' YouTrack inbox notifications, constituting a confidentiality breach. There is also a low integrity impact, as the ability to interact with or manipulate another user's inbox threads may allow limited unauthorized modifications. Availability is not affected. The scope of impact is limited to the YouTrack application itself, with no evidence of lateral movement potential beyond the platform (GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable per SSVC assessment, as it requires an authenticated session (GitHub Advisory).
JetBrains has released a fix in YouTrack version 2026.2.19422. All users should upgrade to this version or later as the primary remediation. No specific configuration-based workaround has been published; until patching is possible, administrators should review access logs for anomalous inbox API activity and consider restricting YouTrack access to trusted networks or VPN (JetBrains, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."