PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75048 JetBrains CVE debrief

CVE-2026-75048 is a stored XSS vulnerability in JetBrains YouTrack, specifically in the fenced code-block language label feature. The vulnerability has a CVSS score of 8.2 and is considered HIGH severity. Defenders responsible for JetBrains YouTrack instances, particularly those with public access or used by multiple users, should assess exposure and apply remediation. The CVE record and NVD entry provide limited information about the vulnerability, with the primary details coming from the vendor advisory. An attacker could inject malicious code, potentially leading to security issues. The debrief is based on the supplied source corpus and CVE details.

Vendor
JetBrains
Product
YouTrack
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-15
Advisory published
2026-08-17
Advisory updated
2026-09-15

Who should care

Defenders responsible for JetBrains YouTrack instances, particularly those with public access or used by multiple users, should assess exposure and apply remediation.

Why it matters

CVE-2026-75048 is a stored XSS vulnerability in JetBrains YouTrack that could lead to security issues if left unpatched. Defenders should prioritize verifying exposure and applying remediation.

  • Potential for malicious code injection and execution
  • Possible impact on users viewing affected code blocks
  • Need for verification of exposure and application of remediation
  • Potential for security issues if left unpatched

Technical summary

CVE-2026-75048 is a stored XSS vulnerability in JetBrains YouTrack, specifically in the fenced code-block language label feature. An attacker could inject malicious code, potentially leading to security issues. The vulnerability has a CVSS score of 8.2 and is considered HIGH severity.

Defensive priority

Defenders should prioritize verifying exposure and applying remediation for JetBrains YouTrack instances, particularly those with public access or used by multiple users.

Recommended defensive actions

  • Verify the version of JetBrains YouTrack and check if it's vulnerable (prior to 2026.2.18068)
  • Apply the patch (2026.2.18068) or later to fix the stored XSS vulnerability
  • Review and restrict user input and permissions for creating and editing fenced code blocks
  • Monitor for suspicious activity related to code block creation and editing

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability, with the primary details coming from the vendor advisory. Evidence is limited to CVE and NVD entries, with no additional public information available. Defenders should verify exposure and apply remediation for JetBrains YouTrack instances, particularly those with public access or used by multiple users. The vulnerability has a CVSS score of 8.2 and is considered HIGH severity. The NVD entry and CVE record

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75048 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75048

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75048 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75048

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.