Impact
An authentication bypass flaw in JetBrains YouTrack enables an attacker to download database backups through a shared draft signature, exposing the entire contents of the database to an unauthenticated user. The vulnerability can lead to the exfiltration of sensitive project information, user data, and potentially internal corporate secrets. The high CVSS score of 9.1 reflects the severe impact and ease of exploitation once a valid shared draft signature is obtained.
Affected Systems
JetBrains YouTrack instances running any version before 2025.3.156085, 2026.1.13913, or 2026.2.18112 are affected. The issue is specific to the backup export path that can be accessed via a draft signature link and does not require additional credentials.
Risk and Exploitability
The CVSS severity indicates a critical risk, while the EPSS score is not available, leaving uncertainty about how frequently the flaw is being exploited in the wild. The vulnerability is not currently listed in the CISA KEV catalog, suggesting it may not be in active use by known threat actors yet. The attack vector is likely remote, via HTTP requests to the backup endpoint, and requires only an untrusted shared draft signature generated by a legitimate user.
OpenCVE Enrichment