Impact
JetBrains YouTrack software permits an unauthorized transfer of a project from one organisation to another without the necessary authorisation checks. This flaw allows a user to move a project between organisations, potentially exposing project data to unintended recipients and violating organisational boundaries. The weakness is a missing or inadequate authorisation control, corresponding to CWE-862 and enabling a direct integrity and confidentiality breach.
Affected Systems
The vulnerability is present in all JetBrains YouTrack releases released before version 2026.2.17917. No specific sub‑versions are listed, so all older releases may be affected. No other products or vendors are identified.
Risk and Exploitability
The CVSS score of 8.1 reflects a high severity impact. EPSS data is not available, and the vulnerability is not listed in CISA's KEV. The likely attack vector is the YouTrack web interface, where an authenticated user can submit a project transfer request that bypasses authorisation checks. An attacker exploiting this flaw can move a project to an organisation they control or to a target organisation, enabling unauthorized data access and potentially facilitating further attacks on that organisation's resources.
OpenCVE Enrichment