Impact
JetBrains YouTrack suffered an improper access control flaw that permitted users to enumerate restricted issues and articles displayed on the Planning Canvas. The vulnerability, identified as a CWE‑639 flaw, enables a non‑privileged or improperly authorized user to view data that should be protected, compromising confidentiality of project information.
Affected Systems
The affected product is JetBrains YouTrack. All installations running a version earlier than 2026.1.13570 are vulnerable. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. The likely attack path involves accessing the Planning Canvas through normal user privileges; no additional exploits are described, implying the vulnerability can be leveraged in routine use of the application.
OpenCVE Enrichment