Impact
The vulnerability allows an authenticated user to discover other user accounts in JetBrains YouTrack by querying the users search endpoint. This can expose usernames and enable additional credential‑guessing or social engineering attacks. The weakness is a missing authorization check (CWE‑862).
Affected Systems
JetBrains YouTrack installations running a version earlier than 2026.2.18112 are affected. Any instance that exposes the users search endpoint to authenticated accounts can be targeted.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability is considered low severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. Attackers must first obtain valid credentials to an account in the system; once authenticated they can send requests to the users search endpoint, enumerating account names. No special network privileges or conditions beyond legitimate authentication are required, making this vulnerability an obvious target for threat actors with access to the application.
OpenCVE Enrichment