External risk intelligence

JetBrains YouTrack Account Takeover Via Notification Signature Replay.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-100277

JetBrains YouTrack is a project management and issue tracking software frequently deployed as a public-facing web application or accessible service portal for teams and external stakeholders, making it commonly reachable from the internet in standard business configurations.

Jetbrains Youtrack

before 2026.2.19197

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in JetBrains YouTrack software could allow unauthorized account takeover. This issue impacts the security of user accounts within the YouTrack platform, which is used for project management and issue tracking. The primary concern is confirming the relevance and exposure of this vulnerability to our environment.

  • Attackers can take over accounts.
  • Protects our project management system.
  • Confirm YouTrack relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted network requests to a vulnerable YouTrack instance. This would involve interacting with the notification system to replay a signature, which could then lead to an attacker gaining unauthorized access to user accounts.

  • No user interaction required.
  • Replay notification signature.
  • Leads to account takeover.

Live Threat

Current exploitation, exposure, and threat context

Account takeover may be possible when notification signatures can be replayed, potentially affecting access to user accounts and system data within JetBrains YouTrack. This occurs when specific conditions allow for the replaying of notification signatures.

  • User account access and system data.
  • Replaying notification signatures.
  • Unauthorized access and control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in JetBrains YouTrack requires immediate attention from teams managing application security and infrastructure. The first critical step is to identify all YouTrack instances across the environment, determine their internet reachability and business criticality, and then locate the specific asset owners responsible for remediation. Planning should prioritize high-risk assets, potentially involving vendor coordination if direct patching is not immediately feasible.

  • Application owners should lead the response.
  • Verify YouTrack instance reachability and criticality.
  • Plan remediation based on identified risks.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is JetBrains YouTrack?

JetBrains YouTrack is a project management and issue-tracking platform widely used by teams to organize tasks, manage workflows, and handle customer support tickets. It acts as a central hub where developers and stakeholders collaborate, often hosting sensitive project documentation, code references, and internal communication, which makes its security essential for protecting team productivity and data.

How does CWE-863 impact CVE-2026-100277?

This vulnerability is classified under CWE-863, which refers to Incorrect Authorization. In this specific case, the software fails to properly verify the uniqueness or one-time nature of a notification signature. Because the system accepts a previously used signature as valid, an unauthorized party can replay it to impersonate a legitimate user and gain full access to their account.

What triggers the account takeover vulnerability?

The flaw is triggered when an attacker intercepts and replays a valid notification signature associated with the YouTrack system. Simply accessing the site or viewing a standard page does not trigger this issue; the attacker must specifically interact with the notification mechanism to resubmit the captured signature to the server.

Why is this CVE concerning for internet-facing instances?

According to Halo Surface Signal, YouTrack is frequently deployed as a public-facing web application to enable access for external stakeholders and remote teams. Since the attack vector for this vulnerability is network-based and requires no user interaction, instances reachable from the internet are at a higher risk of being targeted than those strictly isolated within an internal network.

What is the first step to address this issue?

Your priority is to identify all YouTrack installations within your organization. Once you have a complete inventory, verify which instances are accessible over the internet and determine their business criticality. Coordinate with the designated application owners for these systems to plan the necessary updates, ensuring that high-risk, public-facing instances are remediated first.

References