Skip to main content

Vendor archive

jetbrains CVEs

Beta · best-effort

597 CVEs tagged to vendor jetbrains48 Critical, 137 High, 347 Medium, 65 Low, 0 Unrated.

CVE-2026-57923

Published Jun 26, 2026

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57922

Published Jun 26, 2026

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57921

Published Jun 26, 2026

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53914

Published Jun 26, 2026

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56142

Published Jun 19, 2026

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to account…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56141

Published Jun 19, 2026

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-53915

Published Jun 19, 2026

In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-50242

Published Jun 19, 2026

In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to adminis…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49386

Published May 29, 2026

In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49385

Published May 29, 2026

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49384

Published May 29, 2026

In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49383

Published May 29, 2026

In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49382

Published May 29, 2026

In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin

CVSS 4.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49381

Published May 29, 2026

In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible

CVSS 3.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49380

Published May 29, 2026

In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49379

Published May 29, 2026

In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49378

Published May 29, 2026

In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49377

Published May 29, 2026

In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49376

Published May 29, 2026

In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49375

Published May 29, 2026

In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49374

Published May 29, 2026

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49373

Published May 29, 2026

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49372

Published May 29, 2026

In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49371

Published May 29, 2026

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49370

Published May 29, 2026

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

CVSS 3.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 26-50 of 597 CVEsPage 2 of 24