CVE-2026-75045
9.1JetBrains · YouTrack
JetBrains YouTrack is vulnerable to unauthorized database backup downloads by unauthenticated attackers due to an issue with shared draft signatures.
Executive summary
An unauthenticated access vulnerability in JetBrains YouTrack allows remote attackers to download sensitive database backups by manipulating shared draft signatures.
Vulnerability
The vulnerability originates from a flaw in how shared draft signatures are processed, allowing unauthenticated users to bypass authentication checks and download full database backups.
Business impact
The potential exposure of full database backups is catastrophic, as these files contain sensitive intellectual property, user credentials, and internal project data. Given the CVSS score of 9.1, this vulnerability poses a severe risk of data breach and long-term reputational damage to organizations relying on YouTrack for project management.
Remediation
Immediate Action: Upgrade to the latest version of YouTrack as specified in the vendor security advisory to remediate the signature validation flaw.
Proactive Monitoring: Monitor server logs for unauthorized access attempts to backup download endpoints and inspect audit logs for suspicious data export activities.
Compensating Controls: Ensure the YouTrack instance is not directly exposed to the public internet and use network-level access controls to restrict access to authorized users only.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
This vulnerability represents an existential risk to the confidentiality of project data. Organizations should prioritize updating their YouTrack instances immediately and perform a thorough audit of access logs to ensure that no unauthorized data exfiltration has occurred.