
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-57926 is a prototype pollution vulnerability in the websandbox bridge of JetBrains YouTrack, a popular issue tracking and project management platform. It affects all YouTrack versions before 2026.2.16593 and was publicly disclosed on June 26, 2026. The NVD assigns a CVSS v3.1 base score of 9.8 (Critical), while the ENISA EUVD entry (EUVD-2026-39658) assigns a lower vendor-assessed score of 2.6 (Low), reflecting differing assessments of exploitability preconditions (JetBrains Advisory).
The vulnerability is classified as CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes — 'Prototype Pollution'). The websandbox bridge in YouTrack fails to properly sanitize or restrict user-controlled input before it is used to set properties on JavaScript objects, allowing an attacker to inject properties into Object.prototype. This can alter the behavior of the application's runtime by modifying shared prototype properties that downstream code relies upon. The attack vector is network-based, and exploitation requires crafting a malicious request targeting the websandbox bridge component (JetBrains Advisory).
Successful exploitation can allow an authenticated attacker to tamper with the application's runtime state by polluting shared object prototypes, potentially leading to unauthorized modification of application behavior, bypassing of access controls, or disruption of service availability. The NVD's critical scoring reflects potential high impacts across confidentiality, integrity, and availability, though the vendor's own assessment suggests a more limited integrity impact under realistic exploitation conditions. Lateral movement or direct data exfiltration is not directly implied, but prototype pollution can serve as a stepping stone for more complex attack chains within the application context (JetBrains Advisory).
__proto__, constructor, or prototype with attacker-controlled values.Object.prototype.__proto__, constructor, or prototype.JetBrains has released a patch in YouTrack version 2026.2.16593, which resolves this vulnerability. Organizations should upgrade to version 2026.2.16593 or later as the primary remediation step. As interim measures, restrict access to YouTrack instances to trusted and necessary users only, and implement network-level controls to limit exposure. Input validation and sanitization for all user inputs processed by the websandbox bridge is also recommended as a defense-in-depth measure (JetBrains Advisory).
Coverage of CVE-2026-57926 has been limited to automated vulnerability tracking platforms and aggregators such as Vulners, CVEfeed, VulDB, and Tenable's plugin pipeline. BeyondMachines noted JetBrains patched multiple flaws across their application ecosystem in the same release cycle. No significant independent researcher commentary or major media coverage has been identified for this specific CVE (BeyondMachines).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."