Impact
An improper permission check in JetBrains YouTrack before 2026.2.18634 permits an attacker to overwrite bundled applications through the app import endpoint. This flaw can allow an adversary to replace legitimate bundled apps with malicious ones, potentially leading to unauthorized code execution or persistence on a compromised instance. The weakness is specifically a missing or flawed authorization check (CWE-863).
Affected Systems
The vulnerability affects JetBrains YouTrack installations running versions earlier than 2026.2.18634. Administrators must verify the exact build number for their deployment.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote, through the publicly accessible app import endpoint; an attacker would need authentication or privileged access to target the endpoint. Given the absence of a publicly known exploit, the exploitation likelihood is currently unknown, but the potential impact on confidentiality, integrity, and availability warrants prompt remediation.
OpenCVE Enrichment