<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Youtrack on CVE Alert &amp; Security Feed</title><link>https://cvealert.net/products/youtrack/</link><description>Recent content in Youtrack on CVE Alert &amp; Security Feed</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 01 Oct 2026 10:17:15 +0000</lastBuildDate><atom:link href="https://cvealert.net/products/youtrack/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-103495</title><link>https://cvealert.net/posts/cve-2026-103495/</link><pubDate>Thu, 01 Oct 2026 10:17:15 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-103495/</guid><description>In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs</description></item><item><title>CVE-2026-103496</title><link>https://cvealert.net/posts/cve-2026-103496/</link><pubDate>Thu, 01 Oct 2026 10:17:15 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-103496/</guid><description>In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users&amp;rsquo; notifications</description></item><item><title>CVE-2026-103497</title><link>https://cvealert.net/posts/cve-2026-103497/</link><pubDate>Thu, 01 Oct 2026 10:17:15 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-103497/</guid><description>In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration</description></item><item><title>CVE-2026-103491</title><link>https://cvealert.net/posts/cve-2026-103491/</link><pubDate>Thu, 01 Oct 2026 10:17:14 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-103491/</guid><description>In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues</description></item><item><title>CVE-2026-103492</title><link>https://cvealert.net/posts/cve-2026-103492/</link><pubDate>Thu, 01 Oct 2026 10:17:14 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-103492/</guid><description>In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments</description></item><item><title>CVE-2026-103493</title><link>https://cvealert.net/posts/cve-2026-103493/</link><pubDate>Thu, 01 Oct 2026 10:17:14 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-103493/</guid><description>In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible</description></item><item><title>CVE-2026-103494</title><link>https://cvealert.net/posts/cve-2026-103494/</link><pubDate>Thu, 01 Oct 2026 10:17:14 +0000</pubDate><guid>https://cvealert.net/posts/cve-2026-103494/</guid><description>In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes</description></item></channel></rss>