CVE-2026-100261
In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
CVSS
5.4
Medium
EPSS
0.2%
p6
KEV
—
Exploit Today
2
0-100
Published: Sep 30, 2026 · Last modified: Oct 2, 2026 · CWE-288
0.2%EPSS · 30 days0.2%
2026-10-012026-10-04
In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-888285.4 MED5.4%
——2The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.6dCVE-2026-634938.1 HIG17.2%
——5Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challenge because CheckForTwoFactor is enforced in the web middleware group but not the API middleware group. The advisory states that the resulting persistent API token can read and modify resources with the victim's permissions and, for an administrator, can reach the users/two_factor_reset endpoint. Resetting the administrator's enrolled second factor allows the password-holding attacker to enroll an attacker-controlled factor, take over the administrator's web account, and lock out the legitimate user. The token does not create a web session, but it provides broad API access while the same browser session remains blocked at the two-factor page. This vulnerability is fixed in 8.7.0.5dCVE-2026-90481—23.8%
——7In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.10dCVE-2026-79680—25.5%
——8Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain unauthorized remote access to the shared application, compromising the confidentiality and integrity of the session.10dCVE-2026-939287.3 HIG32.0%
——10Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass.
This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8.12dCVE-2026-582698.1 HIG12.0%
——4Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full access and refresh JWTs without checking whether the account has TOTP 2FA enabled. An attacker with stolen or phished credentials can bypass 2FA in a single request. The parallel login endpoint (`POST /api/auth/login`) correctly enforces 2FA by calling `setCookies(user, res, true)`, which gates on `user.twoFaEnabled`. Version 2.4.0 patches the issue.10d