Impact
In JetBrains YouTrack versions before 2026.2.18634 the generic VCS webhook handler does not enforce authentication when the webhook secret is left blank. The missing authentication check (CWE-306) allows an unauthenticated user to trigger the webhook endpoint, potentially enabling unauthorized actions through the VCS integration (this is inferred).
Affected Systems
JetBrains YouTrack is affected in all releases prior to 2026.2.18634. Any deployed instance that uses a VCS webhook endpoint and has not yet applied the 2026.2.18634 update is vulnerable. Administrators should verify the current YouTrack version and plan a timely upgrade to a patched release.
Risk and Exploitability
The CVSS score of 3.7 indicates low to medium severity. EPSS information is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Given that the webhook endpoint is exposed over the network, it is likely that an attacker could reach it over the network (this is inferred). While the exploitation likelihood is uncertain and the impact does not immediately lead to full system compromise, the flaw provides a foothold for potential misuse of the VCS integration and should be addressed promptly.
OpenCVE Enrichment