CVE-2026-75048
8.2JetBrains · YouTrack
A stored cross-site scripting vulnerability exists in JetBrains YouTrack, allowing remote attackers to execute arbitrary scripts in the context of a user session.
Executive summary
A cross-site scripting vulnerability in JetBrains YouTrack allows for potential unauthorized script execution and information disclosure within the application environment.
Vulnerability
The application is affected by a cross-site scripting (CWE-79) vulnerability. An unauthenticated attacker can leverage this flaw via a crafted interaction to execute malicious scripts in the context of a victim's session.
Business impact
This vulnerability poses a significant risk to data confidentiality and integrity, as attackers could potentially steal session tokens or perform actions on behalf of authenticated users. With a CVSS score of 8.2, the potential for unauthorized access to project management data warrants immediate attention to protect sensitive organizational information.
Remediation
Immediate Action: Upgrade to JetBrains YouTrack version 2026.2.18068 or later.
Proactive Monitoring: Review web access logs and application audit trails for anomalous patterns indicative of XSS attempts, such as unusual URL parameters or script-like characters.
Compensating Controls: Implement a strong Content Security Policy (CSP) to mitigate the impact of potential cross-site scripting attacks.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the severity of cross-site scripting in a collaborative environment like YouTrack, administrators should prioritize the application of the vendor-provided security update. Ensuring all users are on the latest version is critical to maintaining the security of the platform.