Impact
The vulnerability exists in JetBrains YouTrack versions earlier than 2026.2.18634. Improper permission checks let users who are only granted read‑only access create or modify whiteboard cards. This flaw, classified as CWE‑863, allows an attacker to alter project board data, compromising data integrity and potentially affecting team coordination.
Affected Systems
JetBrains YouTrack, all releases before 2026.2.18634, are affected. The fix is included in version 2026.2.18634 and later.
Risk and Exploitability
The CVSS score of 6.5 denotes medium severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. An attacker could exploit the flaw via the web interface or the API, accessing the system as a read‑only user to create or edit whiteboard cards, but the attack does not provide code execution or broader system compromise.
OpenCVE Enrichment