PatchSiren cyber security CVE debrief
CVE-2026-75048 JetBrains CVE debrief
CVE-2026-75048 is a stored XSS vulnerability in JetBrains YouTrack, specifically in the fenced code-block language label feature. The vulnerability has a CVSS score of 8.2 and is considered HIGH severity. Defenders responsible for JetBrains YouTrack instances, particularly those with public access or used by multiple users, should assess exposure and apply remediation. The CVE record and NVD entry provide limited information about the vulnerability, with the primary details coming from the vendor advisory. An attacker could inject malicious code, potentially leading to security issues. The debrief is based on the supplied source corpus and CVE details.
- Vendor
- JetBrains
- Product
- YouTrack
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-15
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-15
Who should care
Defenders responsible for JetBrains YouTrack instances, particularly those with public access or used by multiple users, should assess exposure and apply remediation.
Why it matters
CVE-2026-75048 is a stored XSS vulnerability in JetBrains YouTrack that could lead to security issues if left unpatched. Defenders should prioritize verifying exposure and applying remediation.
- Potential for malicious code injection and execution
- Possible impact on users viewing affected code blocks
- Need for verification of exposure and application of remediation
- Potential for security issues if left unpatched
Technical summary
CVE-2026-75048 is a stored XSS vulnerability in JetBrains YouTrack, specifically in the fenced code-block language label feature. An attacker could inject malicious code, potentially leading to security issues. The vulnerability has a CVSS score of 8.2 and is considered HIGH severity.
Defensive priority
Defenders should prioritize verifying exposure and applying remediation for JetBrains YouTrack instances, particularly those with public access or used by multiple users.
Recommended defensive actions
- Verify the version of JetBrains YouTrack and check if it's vulnerable (prior to 2026.2.18068)
- Apply the patch (2026.2.18068) or later to fix the stored XSS vulnerability
- Review and restrict user input and permissions for creating and editing fenced code blocks
- Monitor for suspicious activity related to code block creation and editing
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, with the primary details coming from the vendor advisory. Evidence is limited to CVE and NVD entries, with no additional public information available. Defenders should verify exposure and apply remediation for JetBrains YouTrack instances, particularly those with public access or used by multiple users. The vulnerability has a CVSS score of 8.2 and is considered HIGH severity. The NVD entry and CVE record
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75048 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75048
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75048 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75048
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jetbrains.com/privacy-security/issues-fixed/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.