Description
In JetBrains YouTrack before 2025.3.156085,
2026.1.13913,
2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
Published: 2026-08-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication bypass flaw in JetBrains YouTrack enables an attacker to download database backups through a shared draft signature, exposing the entire contents of the database to an unauthenticated user. The vulnerability can lead to the exfiltration of sensitive project information, user data, and potentially internal corporate secrets. The high CVSS score of 9.1 reflects the severe impact and ease of exploitation once a valid shared draft signature is obtained.

Affected Systems

JetBrains YouTrack instances running any version before 2025.3.156085, 2026.1.13913, or 2026.2.18112 are affected. The issue is specific to the backup export path that can be accessed via a draft signature link and does not require additional credentials.

Risk and Exploitability

The CVSS severity indicates a critical risk, while the EPSS score is not available, leaving uncertainty about how frequently the flaw is being exploited in the wild. The vulnerability is not currently listed in the CISA KEV catalog, suggesting it may not be in active use by known threat actors yet. The attack vector is likely remote, via HTTP requests to the backup endpoint, and requires only an untrusted shared draft signature generated by a legitimate user.

Generated by OpenCVE AI on August 17, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a fixed version of YouTrack (2025.3.156085 or later, 2026.1.13913 or later, 2026.2.18112 or later).
  • Disable or restrict the shared draft signature feature that permits backup download or enforce authentication on the backup endpoint.
  • Monitor YouTrack logs for unauthorized backup download attempts and block offending IP addresses.

Generated by OpenCVE AI on August 17, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Database Backup Download via Shared Draft Signature
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-08-18T03:55:40.911Z

Reserved: 2026-08-17T15:34:06.594Z

Link: CVE-2026-75045

cve-icon Vulnrichment

Updated: 2026-08-17T19:20:31.475Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-17T16:17:51.530

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-75045

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T18:00:05Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel