Impact
Unchecked group membership changes in JetBrains YouTrack allow an attacker to arbitrarily modify group memberships and elevate privileges, potentially gaining full administrative control. The weakness is a privilege or access control failure (CWE-266) and could compromise confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerability affects JetBrains YouTrack for versions prior to 2026.2.18634. Users running any older build lack the fix that checks group membership changes before applying them.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires ability to alter group membership, which can be achieved through the web UI or API by users with sufficient permissions; therefore the attack vector is likely remote via the application interface.
OpenCVE Enrichment