Junglewise Threat Intelligence

CVE-2026-49368: JetBrains YouTrack stored XSS in project notification templates

CVE-2026-49368 · Severity: high · CVSS 8.7 · Published 2026-05-29

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack, a project management and issue tracking tool, was vulnerable to a security flaw in its notification template system. An attacker with basic user permissions could inject malicious scripts that would execute in the browsers of other users, including administrators. This could lead to unauthorized access to sensitive project data, session hijacking, or the performance of actions on behalf of other users.

Technical details

A stored cross-site scripting (XSS) vulnerability (CWE-79) existed in JetBrains YouTrack before version 2026.1.13162. The flaw was located in the project notification templates component, where input was not properly neutralized before being rendered in the web interface. An authenticated attacker with low privileges could inject malicious scripts into these templates. When other users, such as project managers or administrators, view or interact with these notifications, the script executes in their browser context. This can lead to full session compromise or unauthorized data exfiltration. The issue has been addressed in version 2026.1.13162.

Affected products

  • JetBrains YouTrack before 2026.1.13162

Timeline

  • 2026-05-29: advisory: CVE-2026-49368 published by JetBrains
  • 2026-05-29: patched: Fixed in version 2026.1.13162

References

Related threats