CVE-2026-75051

8.1

JetBrains · YouTrack

JetBrains YouTrack prior to version 2026.2.17917 contains a missing authorization vulnerability (CWE-862) that allows authenticated users to perform unauthorized actions.

Executive summary

A missing authorization vulnerability in JetBrains YouTrack allows authenticated attackers to gain unauthorized access to sensitive data and system functions.

Vulnerability

This vulnerability is a missing authorization flaw (CWE-862) where the application fails to properly verify user permissions. It requires the attacker to have low-level privileges (authenticated access) to exploit the flaw.

Business impact

The ability for an authenticated user to bypass authorization checks can lead to significant data exposure or modification within the project management environment. With a CVSS score of 8.1, this is classified as a high-severity issue that could compromise the integrity and confidentiality of sensitive project tracking data.

Remediation

Immediate Action: Update JetBrains YouTrack to version 2026.2.17917 or later to resolve the missing authorization flaw.

Proactive Monitoring: Review application access logs for unusual administrative actions or access to projects that fall outside of the assigned user role scope.

Compensating Controls: Ensure that internal network access to the YouTrack instance is restricted to authorized personnel only, limiting the pool of potential attackers.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score, organizations should prioritize patching this vulnerability to prevent potential privilege escalation or unauthorized data manipulation. Please verify the current version of your YouTrack installation and apply the update to the mandated version immediately.

More JetBrains CVEs