PT-2026-52706 · Jetbrains · Youtrack

CVE-2026-57926

·

Published

2026-06-26

·

Updated

2026-06-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JetBrains YouTrack versions prior to 2026.2.16593
Description The websandbox bridge is susceptible to prototype pollution, a condition where an attacker can manipulate the prototype of a JavaScript object to inject properties or change the behavior of the application.
Recommendations Update to version 2026.2.16593.

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57926

Affected Products

Youtrack