Impact
A flaw in YouTrack allows the watchRules and issueListConfig endpoints to expose private saved searches, revealing confidential filter configurations and query data. The weakness is a classic Authorization Bypass (CWE‑639) that can compromise confidentiality by leaking user‑specific information. The exposed data could enable attackers to reconstruct sensitive workflows, project details, or user intent.
Affected Systems
The vulnerability affects JetBrains YouTrack installations running any version older than 2026.2.18634. No other vendors or products are impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is currently unavailable, while the advisory is not listed in the CISA KEV catalog. Attackers can likely trigger the exploit by sending requests to the vulnerable endpoints, which may not require elevated privileges. The exposure could occur to any authenticated or possibly unauthenticated user, depending on the current configuration of YouTrack.
OpenCVE Enrichment