Skip to content

JetBrains vulnerabilities are hard to triage and patch

Security9 posts from 9 people1d active+99 posts in the last 7 days, 0 the 7 days before (new)

Posts per day

Posts per day9 posts, Sep 30 to Oct 2

The posts behind it

9, newest first
PostDate
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signaturejetbrains: In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signatureAdvisories (advisories.fru.dev)Sep 302 days ago
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templatesjetbrains: In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templatesAdvisories (advisories.fru.dev)Sep 302 days ago
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code executionjetbrains: In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code executionAdvisories (advisories.fru.dev)Sep 302 days ago
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templatesjetbrains: In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templatesAdvisories (advisories.fru.dev)Sep 302 days ago
In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted addressjetbrains: In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted addressAdvisories (advisories.fru.dev)Sep 302 days ago
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password resetjetbrains: In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password resetAdvisories (advisories.fru.dev)Sep 302 days ago
In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projectsjetbrains: In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projectsAdvisories (advisories.fru.dev)Sep 302 days ago
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSLjetbrains: In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSLAdvisories (advisories.fru.dev)Sep 302 days ago
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settingsjetbrains: In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settingsAdvisories (advisories.fru.dev)Sep 302 days ago

Companies and products named

Company or productPosts naming it
JetBrains9
About this problem

Evidence

9 posts from 9 people in 1 place, about 9 a week over 1 days. Mostly on Advisories (advisories.fru.dev).

Frustration Frustration 0 of 3· Seen on fru.dev sites

How it was grouped

Posts that state a pain and match the "vuln-noise" rule about JetBrains. First post Sep 30, 2026, latest Sep 30, 2026. Corroborated: 3 or more posts from 2 or more people or places. Method

Other JetBrains problems

History

  • 2026-10-02 Added: JetBrains vulnerabilities are hard to triage and patch (9 posts)

Rising problems by email

Mondays: the problems in data, tech and AI that grew fastest that week.

Double opt-in. Unsubscribe any time.