Impact
In JetBrains YouTrack, a missing authorization check in the REST API created an IDOR flaw that permitted users who should not have access to read or modify restricted data. This weakness corresponds to CWE‑862 (Missing Authorization). The impact is a direct compromise of confidentiality, allowing attackers to retrieve sensitive project or issue information, and potentially affecting integrity if the API permits write operations.
Affected Systems
All JetBrains YouTrack versions prior to 2026.2.18788, 2026.1.14055, or 2025.3.161254 are affected; any earlier release remains vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 8 indicates a high‑severity vulnerability. EPSS data is not available, so exploitation probability is uncertain, but the flaw is not listed in the CISA KEV catalog. The likely attack vector is remote, with an attacker sending crafted API requests over the network and exploiting the lack of authorization checks to access protected resources. Prerequisites for exploitation are minimal, requiring only knowledge of valid identifiers and connectivity to the YouTrack service.
OpenCVE Enrichment