Impact
JetBrains YouTrack, versions prior to 2026.1.13162, contain an information disclosure flaw via fetchApp requests. The vulnerability allows an attacker to retrieve sensitive data from the server, exposing information that should be protected. It is a classic Information Exposure weakness (CWE‑201).
Affected Systems
All JetBrains YouTrack installations before 2026.1.13162 are affected. This includes any instance of JetBrains YouTrack deployed by organizations using earlier releases.
Risk and Exploitability
The CVSS score of 3.4 indicates a low severity weakness. No EPSS score is available, but the lack of exploitation evidence and the absence from the CISA KEV catalog suggest a low likelihood of being attacked in the wild. The likely attack vector is an unauthenticated or authenticated web request to the /fetchApp endpoint, depending on the system configuration, which can be triggered remotely where the application is exposed.
OpenCVE Enrichment