Impact
In JetBrains YouTrack versions prior to 2026.2.19422 an attacker who could alter user group memberships could raise their privileges beyond what was originally intended. The flaw permits a legitimate user to grant themselves membership in higher‑ranked groups, enabling unauthorized access to protected project data and administrative features. The weakness is categorized as CWE-266, reflecting an improper authorization mechanism that allows privilege escalation.
Affected Systems
The vulnerability affects JetBrains YouTrack. Any deployment of YouTrack running a version earlier than 2026.2.19422 is susceptible. Administrators should verify the exact version and apply the latest available release.
Risk and Exploitability
The CVSS score of 6.6 indicates a moderate severity impact. EPSS data is not available, so the likelihood of exploitation cannot be quantified at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through authenticated use of the web interface or API that allows group membership changes, meaning an attacker with standard user access could exploit the flaw after authenticating. Once the privilege escalation is achieved, the attacker can modify project settings, view confidential issues, and perform actions reserved for administrators.
OpenCVE Enrichment