Impact
JetBrains YouTrack versions prior to 2026.2.18769 allow a project administrator to change a mailbox host without re‑authentication. This flaw enables the administrator to exfiltrate the stored mailbox credentials, exposing sensitive account information. The vulnerability is an information exposure flaw identified as CWE‑201.
Affected Systems
JetBrains YouTrack before 2026.2.18769 is affected. The issue applies to all instances of YouTrack where mailbox integration is configured and used by project administrators.
Risk and Exploitability
The flaw carries a CVSS score of 6.8, indicating a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exfiltration is limited to users with project administrator privileges; no external attacker can exploit the flaw directly. The most likely attack vector involves an internal user with appropriate permissions changing the mailbox host and reading the credentials that were stored in the system.
OpenCVE Enrichment