Impact
An authenticated user of JetBrains YouTrack can abuse the draft creation endpoint to read restricted articles belonging to other projects. The flaw does not provide remote code execution or denial‑of‑service capabilities; it simply allows the disclosure of sensitive content that should be confined within specific project boundaries. The weakness is a classic example of improper authorization, indexed as CWE‑862.
Affected Systems
JetBrains YouTrack versions prior to 2026.1.13903 and 2026.2.17950 are affected. Administrators should verify that their installations are not running these or earlier releases, as the vulnerability exists in all builds before the stated cut‑offs.
Risk and Exploitability
The CVSS score of 6.5 places the vulnerability in the medium severity range. No EPSS score is available, and the issue is not listed in CISA KEV, indicating no known active exploitation campaigns. However, because the attack requires valid user credentials, an internal attacker or compromised account can easily exploit the flaw by sending a normal draft creation request. The impact is limited to confidentiality leakage of project‑restricted content, but the attack vector remains intra‑organization and requires no special privileges beyond legitimate authentication.
OpenCVE Enrichment