Impact
In JetBrains YouTrack versions prior to 2026.2.19422, an attacker could exploit a missing authorization check when working with user group links, allowing elevation of privileges. This weakness permits a user with basic rights to create or modify group links and thereby gain higher privileges, compromising the confidentiality, integrity, and overall control of the system.
Affected Systems
The vulnerability affects JetBrains YouTrack older than version 2026.2.19422. No other vendors or products are listed. The elevated access can apply system‑wide if the compromised user is an administrative account.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity threat. EPSS data is not available, but the lack of a KEV listing suggests no known exploitation yet. Attackers would need to interact with user group links, which typically requires authenticated access. Given the high severity and the potential for privilege escalation, organizations should treat this as a critical patch priority.
OpenCVE Enrichment