Impact
JetBrains YouTrack before 2026.2.19422 suffered a flaw in the issue activities API that allowed the iDOR mechanism to expose restricted issues to unauthorized users. The vulnerability results in a breach of confidentiality and effectively grants users credentials they should not possess, matching weakness CWE‑639.
Affected Systems
All installations of JetBrains YouTrack running a version earlier than 2026.2.19422 are susceptible. This includes any deployment of the JetBrains YouTrack product that has not yet applied the 2026.2.19422 update or newer.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating moderate severity, and no EPSS score is currently available. JetBrains has not listed it in the CISA KEV catalog. Based on the description, the attack vector likely requires authenticated access to the issue activities API; if the API is publicly accessible, a threat actor with valid credentials could exploit the flaw to read restricted issues. No evidence of public exploits has been reported.
OpenCVE Enrichment