Impact
The vulnerability in JetBrains YouTrack, present before version 2026.2.19422, is an authorization bypass (CWE-639) that allows an attacker or a user with limited access to read notification inbox threads belonging to other users. This flaw enables the unauthorized disclosure of potentially sensitive information stored in those notifications, compromising confidentiality. No indication is provided that the flaw can be leveraged to alter data or execute code; it focuses solely on information theft via read permissions.
Affected Systems
Affected systems are JetBrains YouTrack installations running any version prior to 2026.2.19422. The vulnerability affects the inbox thread functionality across all supported operating systems and deployment environments (cloud or on‑premises). Specific affected versions are listed only as pre‑2026.2.19422; no finer granularity is provided.
Risk and Exploitability
The CVSS score of 5.4 categorizes this as medium severity. EPSS is not available, so current exploit probability cannot be quantified. The vulnerability is not listed in CISA KEV, indicating no known widespread attacks. Based on the description, the likely attack vector is through normal authenticated user activity, exploiting the permission check for inbox threads. An attacker would need to access a user account or obtain credentials to read another user's inbox notifications.
OpenCVE Enrichment