Impact
JetBrains YouTrack exposes an IDOR in the user profile API that may allow an attacker to view private issues and starred folders belonging to other organizations. This could lead to unauthorized disclosure of sensitive project information and folder metadata, compromising confidentiality and potentially revealing internal workflows and project structures.
Affected Systems
The flaw affects JetBrains YouTrack releases prior to 2026.2.18634. Any instance running an older release is vulnerable. The IDOR is located in the user profile API; the description does not specify whether authenticated access is required to exploit it.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. No EPSS value is available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA KEV. The IDOR is in the user profile API; the description does not state whether authenticated sessions are required. The risk remains moderate, contingent on the ability to invoke the API endpoint.
OpenCVE Enrichment