Description
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
Published: 2026-10-01
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Ability to reload translation catalogs without authorization
Action: Assess Impact
AI Analysis

Impact

JetBrains YouTrack versions prior to 2026.2.19422 suffer from a missing authorization issue that allows an attacker to trigger a reload of translation catalogs. This flaw, classified as CWE‑862, enables an unauthenticated or improperly authorized user to replace or modify the language resources displayed to all users. While it does not provide direct code execution, it could be leveraged to inject deceptive text, conduct phishing through an altered UI, or obscure malicious activities by changing visible messages.

Affected Systems

The vulnerability affects JetBrains YouTrack installations with a version earlier than 2026.2.19422. Any instance running these releases is susceptible, regardless of the hosting environment or deployment model. No additional product or vendor versions are referenced in the current data.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA's KEV catalog, suggesting a lower likelihood of widespread exploitation. The attack vector is inferred to require some level of authenticated access to the YouTrack instance, as the functionality is normally restricted to administrators. However, because the authorization check is omitted, any user with access can exploit the flaw, making it a significant concern for multi-tenant or shared deployments.

Generated by OpenCVE AI on October 1, 2026 at 11:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JetBrains YouTrack to version 2026.2.19422 or later to apply the vendor fix
  • If an upgrade is delayed, remove or disable the ability to trigger translation reloads by revoking the relevant permissions for non-administrative users
  • Monitor YouTrack logs for unexpected reload attempts and correlate them with user activity to detect potential misuse

Generated by OpenCVE AI on October 1, 2026 at 11:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
CPEs cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*:*
Vendors & Products Jetbrains
Jetbrains youtrack

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Reload of Translation Catalogs in JetBrains YouTrack

Thu, 01 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-10-01T13:36:59.805Z

Reserved: 2026-09-30T17:07:14.763Z

Link: CVE-2026-103495

cve-icon Vulnrichment

Updated: 2026-10-01T13:31:14.397Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-01T10:17:15.030

Modified: 2026-10-01T14:25:47.630

Link: CVE-2026-103495

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T11:15:05Z

Weaknesses