Impact
JetBrains YouTrack versions prior to 2026.2.19422 suffer from a missing authorization issue that allows an attacker to trigger a reload of translation catalogs. This flaw, classified as CWE‑862, enables an unauthenticated or improperly authorized user to replace or modify the language resources displayed to all users. While it does not provide direct code execution, it could be leveraged to inject deceptive text, conduct phishing through an altered UI, or obscure malicious activities by changing visible messages.
Affected Systems
The vulnerability affects JetBrains YouTrack installations with a version earlier than 2026.2.19422. Any instance running these releases is susceptible, regardless of the hosting environment or deployment model. No additional product or vendor versions are referenced in the current data.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is unavailable, and the vulnerability is not listed in CISA's KEV catalog, suggesting a lower likelihood of widespread exploitation. The attack vector is inferred to require some level of authenticated access to the YouTrack instance, as the functionality is normally restricted to administrators. However, because the authorization check is omitted, any user with access can exploit the flaw, making it a significant concern for multi-tenant or shared deployments.
OpenCVE Enrichment