Description
In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
Published: 2026-10-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access to restricted issues
Action: Apply Patch
AI Analysis

Impact

JetBrains YouTrack before 2026.2.19422 suffered a flaw in the issue activities API that allowed the iDOR mechanism to expose restricted issues to unauthorized users. The vulnerability results in a breach of confidentiality and effectively grants users credentials they should not possess, matching weakness CWE‑639.

Affected Systems

All installations of JetBrains YouTrack running a version earlier than 2026.2.19422 are susceptible. This includes any deployment of the JetBrains YouTrack product that has not yet applied the 2026.2.19422 update or newer.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.5, indicating moderate severity, and no EPSS score is currently available. JetBrains has not listed it in the CISA KEV catalog. Based on the description, the attack vector likely requires authenticated access to the issue activities API; if the API is publicly accessible, a threat actor with valid credentials could exploit the flaw to read restricted issues. No evidence of public exploits has been reported.

Generated by OpenCVE AI on October 1, 2026 at 10:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade YouTrack to version 2026.2.19422 or later, which removes the iDOR flaw.
  • Ensure API authentication and authorization checks are correctly configured so that only users with proper permissions can access the issue activities endpoint.
  • If an upgrade cannot be applied immediately, restrict or block access to the issue activities API for untrusted hosts or users until a patch is available.

Generated by OpenCVE AI on October 1, 2026 at 10:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*:*

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Thu, 01 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-10-01T13:37:00.345Z

Reserved: 2026-09-30T17:07:13.570Z

Link: CVE-2026-103491

cve-icon Vulnrichment

Updated: 2026-10-01T13:31:18.473Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-01T10:17:14.540

Modified: 2026-10-01T14:28:17.527

Link: CVE-2026-103491

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T11:00:05Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key