Description
In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations
Published: 2026-09-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains YouTrack exposes an IDOR in the user profile API that may allow an attacker to view private issues and starred folders belonging to other organizations. This could lead to unauthorized disclosure of sensitive project information and folder metadata, compromising confidentiality and potentially revealing internal workflows and project structures.

Affected Systems

The flaw affects JetBrains YouTrack releases prior to 2026.2.18634. Any instance running an older release is vulnerable. The IDOR is located in the user profile API; the description does not specify whether authenticated access is required to exploit it.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. No EPSS value is available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA KEV. The IDOR is in the user profile API; the description does not state whether authenticated sessions are required. The risk remains moderate, contingent on the ability to invoke the API endpoint.

Generated by OpenCVE AI on September 7, 2026 at 18:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains YouTrack to 2026.2.18634 or later
  • Restrict access to the user profile API to internal IP ranges or enforce stricter network segmentation
  • Review permissions and revoke unnecessary cross-organization access for user accounts

Generated by OpenCVE AI on September 7, 2026 at 18:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Mon, 07 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-09-07T16:26:45.068Z

Reserved: 2026-09-07T16:13:36.763Z

Link: CVE-2026-86489

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T17:17:27.167

Modified: 2026-09-07T17:17:27.167

Link: CVE-2026-86489

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T19:00:12Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key