Impact
A signed URL that was previously generated for a restricted project icon can be reused, causing an attacker to obtain a copy of an icon that should only be visible to authorized users. This gives the adversary visibility into project structure and potentially other confidential details stored within those icons. The weakness is an Authorization Bypass Through User-controlled Key flaw, indexed as CWE-639.
Affected Systems
JetBrains YouTrack installations running any version earlier than 2026.2.18634 are vulnerable. Only the JetBrains YouTrack product is affected; no other vendors or products are listed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available, so the current exploitation trend cannot be quantified. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is inferred to be remote: an attacker would need a valid signed URL, potentially obtained from a legitimate user or from network traffic, and then query the icon URL again. The exploitation does not require privileged access and can be performed by anyone who can obtain or guess the signed URL.
OpenCVE Enrichment