Impact
The vulnerability is a missing permission check that permits the creation of knowledge base articles in projects to which the actor should not have access. The flaw allows an attacker to add unauthorized content, potentially exposing sensitive information or disrupting project integrity. This weakness is an example of insufficient authorization (CWE-862).
Affected Systems
JetBrains YouTrack installations prior to version 2026.2.18687 are vulnerable. Any user‑defined projects that have not been protected by the missing permission checks can be targeted by attackers using this flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog, implying no widespread exploitation has been reported. Based on the description, it is inferred that an authenticated user can exploit the flaw by creating articles in protected projects, but no further attack steps are documented. The lack of mandatory authorization checks suggests a moderate risk of unauthorized content injection and potential data exposure, but exploitation requires legitimate user authentication.
OpenCVE Enrichment