Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3191 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
4.3
CVE-2026-57921PATCHED
jetbrains · youtrack

CVE-2026-57921: In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment te

Description

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

Affected Products

VendorProductVersions
jetbrainsyoutrack0, 2026.1.13570

References

  • https://www.jetbrains.com/privacy-security/issues-fixed/

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-57921 | JetBrains YouTrack up to 2026.1.13570 Comment Templates Endpoint authorization
→ No new info (linked only)
CVSS 3.14.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.2.16593
CWECWE-862
PublishedJun 26, 2026
Last enriched1d agov2
Trending Score23
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-57924EXP
CVE-2026-57924: In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
Trending: 41
MEDIUMCVE-2026-57926EXP
CVE-2026-57926: In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
Trending: 35
MEDIUMCVE-2026-57922EXP
CVE-2026-57922: In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
Trending: 35
MEDIUMCVE-2026-53914
CVE-2026-53914: In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
Trending: 24
MEDIUMCVE-2026-57925
CVE-2026-57925: In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
Trending: 20

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 26, 2026
Discovered by ZDM
Jun 26, 2026
Patch Available
Jun 26, 2026
Updated: affectedVersions, severity
Jun 26, 2026

Version History

v2
Last enriched 1d ago
v2Tier C1d ago

Updated affected versions to include 2026.1.13570 and changed severity to HIGH.

affectedVersionsseverity
via VulDB
v11d ago

Initial creation