CVE-2026-75044

8.1

JetBrains · YouTrack

JetBrains YouTrack is affected by an access control vulnerability. This flaw allows authenticated users to perform unauthorized actions, leading to potential data or system compromise.

Executive summary

An access control vulnerability in JetBrains YouTrack, identified as CWE-862, requires immediate patching to prevent unauthorized administrative actions.

Vulnerability

The vulnerability is an improper authorization flaw (CWE-862) that allows an authenticated user to perform actions beyond their assigned privileges. It occurs during standard application usage and does not require elevated access to initiate.

Business impact

The ability to bypass authorization checks can lead to unauthorized data access, modification, or destruction of project management information. With a CVSS score of 8.1, this represents a major security risk that could result in severe operational disruption or the compromise of sensitive organizational data within YouTrack.

Remediation

Immediate Action: Update YouTrack to the corresponding fixed version: 2025.3.156085, 2026.1.13914, or 2026.2.18095, depending on the current branch.

Proactive Monitoring: Audit user activity logs to identify suspicious permission escalations or unauthorized configuration changes made by standard users.

Compensating Controls: Implement strict role-based access control (RBAC) and limit user permissions to the absolute minimum required for their roles until the update is applied.

Exploitation status

Public Exploit Available: No confirmed public exploit available.

Analyst recommendation

Organizations should prioritize the update to the specified versions of YouTrack. Ensuring that all users are operating on patched software is the only reliable way to remediate this authorization vulnerability and protect the integrity of your project management assets.

More JetBrains CVEs