Impact
JetBrains YouTrack suffers from a missing access control that allows authorized reporters to see the email addresses of other reporters. The weakness results in a moderate confidentiality impact, evidenced by a CVSS score of 4.3, and could lead to privacy violations or targeted social engineering.
Affected Systems
The vulnerability affects all JetBrains YouTrack Helpdesk installations prior to version 2026.2.18769, regardless of other configuration settings. Users of the Helpdesk module are exposed to this weakness.
Risk and Exploitability
The CVSS score indicates moderate severity, while the EPSS score is not available and the flaw is not listed in the CISA KEV catalogue, suggesting a low to moderate likelihood of exploitation. Based on the description, the likely attack vector is a web‑based interaction with the Helpdesk interface where an authenticated user can request reporter information. No exploit has been reported, and the weakness requires only access to the Helpdesk portal, making the attack path relatively straightforward.
OpenCVE Enrichment