Description
In JetBrains YouTrack before 2026.1.13903,
2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
Published: 2026-08-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated user of JetBrains YouTrack can abuse the draft creation endpoint to read restricted articles belonging to other projects. The flaw does not provide remote code execution or denial‑of‑service capabilities; it simply allows the disclosure of sensitive content that should be confined within specific project boundaries. The weakness is a classic example of improper authorization, indexed as CWE‑862.

Affected Systems

JetBrains YouTrack versions prior to 2026.1.13903 and 2026.2.17950 are affected. Administrators should verify that their installations are not running these or earlier releases, as the vulnerability exists in all builds before the stated cut‑offs.

Risk and Exploitability

The CVSS score of 6.5 places the vulnerability in the medium severity range. No EPSS score is available, and the issue is not listed in CISA KEV, indicating no known active exploitation campaigns. However, because the attack requires valid user credentials, an internal attacker or compromised account can easily exploit the flaw by sending a normal draft creation request. The impact is limited to confidentiality leakage of project‑restricted content, but the attack vector remains intra‑organization and requires no special privileges beyond legitimate authentication.

Generated by OpenCVE AI on August 17, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update for JetBrains YouTrack (upgrade to version 2026.1.13903 or later, or 2026.2.17950 or newer)
  • Revoke or restrict the permission to create drafts for users who do not need this capability, especially if the feature is not required for business processes
  • Monitor YouTrack logs for anomalous draft creation activity and validate that only authorized users are performing such operations

Generated by OpenCVE AI on August 17, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Authenticated Sensitive Article Disclosure via Draft Creation in JetBrains YouTrack

Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Mon, 17 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-08-17T16:16:18.721Z

Reserved: 2026-08-17T15:34:08.067Z

Link: CVE-2026-75049

cve-icon Vulnrichment

Updated: 2026-08-17T16:16:12.859Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-17T16:17:51.987

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-75049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T18:00:05Z

Weaknesses