CVE-2026-75048

8.2

JetBrains · YouTrack

A stored cross-site scripting vulnerability exists in JetBrains YouTrack, allowing remote attackers to execute arbitrary scripts in the context of a user session.

Executive summary

A cross-site scripting vulnerability in JetBrains YouTrack allows for potential unauthorized script execution and information disclosure within the application environment.

Vulnerability

The application is affected by a cross-site scripting (CWE-79) vulnerability. An unauthenticated attacker can leverage this flaw via a crafted interaction to execute malicious scripts in the context of a victim's session.

Business impact

This vulnerability poses a significant risk to data confidentiality and integrity, as attackers could potentially steal session tokens or perform actions on behalf of authenticated users. With a CVSS score of 8.2, the potential for unauthorized access to project management data warrants immediate attention to protect sensitive organizational information.

Remediation

Immediate Action: Upgrade to JetBrains YouTrack version 2026.2.18068 or later.

Proactive Monitoring: Review web access logs and application audit trails for anomalous patterns indicative of XSS attempts, such as unusual URL parameters or script-like characters.

Compensating Controls: Implement a strong Content Security Policy (CSP) to mitigate the impact of potential cross-site scripting attacks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the severity of cross-site scripting in a collaborative environment like YouTrack, administrators should prioritize the application of the vendor-provided security update. Ensuring all users are on the latest version is critical to maintaining the security of the platform.

More JetBrains CVEs