← Vulnerability feed

Vulnerability record · CVE-2026-57926 · published 26 June 2026

CVE-2026-57926: Jetbrains youtrack prototype pollution vulnerability

Jetbrains · Youtrack

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

9.8 CVSS 3.1 Critical EPSS 0.34% · top 75.5% CWE-1321 · Prototype pollution
9.8CVSS 3.1 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
27 Jun 2026Last modified by NVD

Description

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-57926 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-62422Jetbrains youtrack missing authentication for critical function vulnerabilityIn JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct…EPSS 0.61%9.8CVE-2024-54154Jetbrains youtrack relative path traversal vulnerabilityIn JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandboxEPSS 0.74%9.8CVE-2022-24442Jetbrains youtrack code injection vulnerabilityJetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.EPSS 3.8%9.8CVE-2021-43185Jetbrains youtrack injection vulnerabilityJetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.EPSS 2.0%9.8CVE-2021-25770Jetbrains youtrack code injection vulnerabilityIn JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.EPSS 3.5%9.8CVE-2019-12852Jetbrains youtrack server-side request forgery (ssrf) vulnerabilityAn SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.EPSS 1.8%9.8CVE-2019-12850Jetbrains youtrack sql injection vulnerabilityA query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.EPSS 2.1%9.8CVE-2019-12866Jetbrains youtrack insecure direct object reference vulnerabilityAn Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2026-57926), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.