Impact
JetBrains YouTrack versions before 2026.2.18634 exhibit insufficient validation of role assignments, allowing an attacker to alter role assignments and elevate privileges. This is a privilege control failure and is classified as CWE-266. The CVE description does not explicitly state confidentiality or integrity impacts; any such consequences are inferred and not documented in the official data.
Affected Systems
The affected product is JetBrains YouTrack for any build earlier than version 2026.2.18634. Users of those older releases lack the fix that enforces proper group membership checks.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. The description does not specify an exploitation method or prerequisites, so definitive attack vectors are unknown from the data provided.
OpenCVE Enrichment