Description
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
Published: 2026-06-26
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in JetBrains YouTrack allows a disclosure of project settings through the MCP interface. This flaw results in inadvertent exposure of potentially sensitive configuration information. The weakness is rooted in missing authorization checks, as identified by CWE‑862, which permits unauthenticated or improperly authorized users to retrieve project configuration data that should be protected. The vendor classification indicates a low security impact, reflected by a CVSS score of 3.1.

Affected Systems

JetBrains YouTrack versions prior to 2026.2.16593 are affected. Users should verify that their installation is older than this release before applying remediation.

Risk and Exploitability

The CVSS score of 3.1 rates this vulnerability as low severity, and the absence of an EPSS score indicates that no current exploitation data is publicly known. The flaw is not listed in the CISA KeV catalog, suggesting there have been no confirmed large‑scale attacks at this time. The likely attack vector involves accessing the MCP endpoint—presumably via an authenticated session—though the exact requirements are not documented in the advisory. Because the flaw permits disclosure of configuration data, it presents a risk of information leakage, given that project settings may contain details about workflows, dependencies, or integration endpoints. The overall risk level remains low, but the exposure could aid a future attack if combined with additional privileges or other vulnerabilities.

Generated by OpenCVE AI on June 26, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains YouTrack to version 2026.2.16593 or later. This update removes the missing authorization check that permits project settings disclosure.
  • Confirm that access to the MCP endpoint is protected by proper authentication and authorization controls to prevent unauthorized retrieval of project settings.
  • Audit application logs for unexpected MCP activity and consider implementing network segmentation or firewall rules to limit exposure of administrative interfaces.

Generated by OpenCVE AI on June 26, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 26 Jun 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Fri, 26 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Title YouTrack Project Settings Disclosure via MCP

Fri, 26 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 26 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-06-26T13:46:03.260Z

Reserved: 2026-06-26T12:21:23.232Z

Link: CVE-2026-57922

cve-icon Vulnrichment

Updated: 2026-06-26T13:27:51.543Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T16:45:03Z

Weaknesses