Impact
JetBrains YouTrack versions before 2025.3.156085, 2026.1.13914, and 2026.2.18095 contain a missing authorization check that permits any authenticated user to delete arbitrary entities via the mailbox endpoint. The CVE description confirms that the deletion capability is exposed without proper authorization, which can lead to loss of data or configuration items. The impact is a breach of integrity and could potentially affect application availability if critical entities are removed.
Affected Systems
JetBrains YouTrack products are impacted. Affected releases are any version older than 2025.3.156085, 2026.1.13914, or 2026.2.18095.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, indicating a high severity. EPSS data is not provided and the issue is not listed in the CISA KEV catalog. Since the flaw requires an authenticated user, the primary attack vector is likely through the exposed mailbox endpoint over the network. An attacker with valid credentials can target any entity for deletion, leading to data loss. Because the vulnerability does not require local access or specific privileged roles, it poses a significant risk especially in environments where user permissions are broad.
OpenCVE Enrichment