Impact
This vulnerability permits unauthorized disclosure of user and group data via the Users and Groups web pages in JetBrains YouTrack due to inadequate authorization controls (CWE-863). Attackers could obtain sensitive information that should be protected, potentially compromising confidentiality of internal user identities and group membership details.
Affected Systems
JetBrains YouTrack before version 2026.1.13162. Any instance running a pre-13162 build is susceptible on the web application’s Users and Groups sections.
Risk and Exploitability
The CVSS score of 4.3 describes a medium‑severity disclosure. EPSS data is unavailable, and the vulnerability is not listed in KEV, indicating no known widespread exploitation. The most likely attack vector is remote access via the web interface; an attacker who can reach the web application may exploit the flaw to view protected user and group information. No specific exploit requires elevated privileges or additional conditions beyond standard web interface access.
OpenCVE Enrichment