Impact
The vulnerability allows an attacker to bypass authentication in JetBrains YouTrack by directly accessing the database, resulting in administrative privileges. This weakness is reflected by CWE-306 and provides full control over the system, enabling configuration changes, data extraction, and further exploitation. The flaw carries a CVSS score of 10, indicating a very high severity.
Affected Systems
JetBrains YouTrack versions 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429 are affected.
Risk and Exploitability
With a CVSS score of 10 and an EPSS score below 1%, the overall risk is high yet the probability of exploitation is low. The issue is not listed in CISA’s KEV catalog, so no publicly known exploits exist, but the potential impact warrants immediate action. The likely attack vector involves an attacker with database access or the ability to manipulate database queries, inferred from the description. Monitoring for suspicious database activity is advisable while applying the official patch as soon as possible.
OpenCVE Enrichment