CVE-2026-28193

8.8

JetBrains · YouTrack

JetBrains YouTrack versions prior to 2025.3.121962 contain a missing authorization flaw allowing unauthorized applications to send requests to the app permissions endpoint.

Executive summary

A missing authorization vulnerability in JetBrains YouTrack allows authenticated attackers to manipulate application permissions, posing a significant risk to system integrity.

Vulnerability

This vulnerability, categorized as CWE-862 (Missing Authorization), occurs when the application fails to verify the permissions of an application before allowing requests to the app permissions endpoint. The CVSS vector indicates that a low-privileged authenticated attacker can achieve high impact on confidentiality, integrity, and availability.

Business impact

The ability for an unauthorized entity to modify application permissions can lead to complete compromise of the YouTrack environment. With a CVSS score of 8.8, this high-severity flaw could allow attackers to escalate privileges, access sensitive project data, or disrupt development workflows, resulting in severe reputational and operational damage.

Remediation

Immediate Action: Administrators must update JetBrains YouTrack to version 2025.3.121962 or later immediately to resolve the missing authorization flaw.

Proactive Monitoring: Security teams should review application access logs for unusual requests to the permissions endpoint or unauthorized modifications to user and application roles.

Compensating Controls: If immediate patching is not feasible, restrict network access to the YouTrack administration interface to trusted internal segments and apply strict IP whitelisting.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the high CVSS score and the potential for full system compromise, organizations running affected versions of JetBrains YouTrack should prioritize this update within their standard patch management cycle. Failure to address this vulnerability could expose critical development infrastructure to unauthorized administrative actions.

More JetBrains CVEs

Sources