Impact
A crafted WebSocket message exploits an authorization flaw in JetBrains YouTrack, allowing users with read‑only whiteboard rights to alter canvas content. The vulnerability permits an attacker to create or erase drawings, thereby damaging collaboration integrity. It is based on CWE‑863, where insufficient access control lets a low‑privilege user perform higher‑privilege actions.
Affected Systems
JetBrains YouTrack versions prior to 2026.2.18634 are affected.
Risk and Exploitability
The CVSS score of 3.1 classifies this issue as low severity, and the vulnerability is not listed in the CISA KEV catalog. No EPSS data is available, indicating limited observability of exploitation in the wild. The likely attack vector is via a crafted WebSocket message sent to an authenticated user’s session; the attacker must first log in to a read‑only account with whiteboard access.
OpenCVE Enrichment