Impact
The vulnerability in JetBrains YouTrack permits an authenticated user to add themselves to any project team, thereby bypassing the intended authorization controls and gaining access to issues that are otherwise restricted. This constitutes a privilege escalation that can expose confidential project information to users who should not have such visibility. The flaw is rooted in a missing authorization check, which is catalogued as CWE-863.
Affected Systems
JetBrains YouTrack versions released before 2026.2.19422 are affected. Administrators should verify that their installations are not older than this release.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of the issue, while the absence of an EPSS score and lack of a KEV listing suggest that widespread exploitation is not yet documented. The likely attack vector is an authenticated session; any user who can log in to the platform can exploit the flaw without additional privileges. Because the flaw is not a code execution vulnerability, the impact is limited to unauthorized data disclosure within the confines of the user’s authenticated environment.
OpenCVE Enrichment