Impact
JetBrains YouTrack (versions before 2025.3.160480 and 2026.1.14047) has an authorization bypass that allows a user to send HTTP PUT requests to link sub-resources. These requests can modify linked entities without requiring the standard update permission, thereby permitting an attacker to change data such as status, ownership, or relationships. This flaw is identified as CWE-863 and results in integrity violations of protected resources.
Affected Systems
Affected systems are JetBrains YouTrack installations using either the 2025.3.160480 release series or the 2026.1.14047 release series prior to these specific version releases. All users with any authenticated session who can craft the request can exploit the flaw.
Risk and Exploitability
The vulnerability has a CVSS score of 7.7 indicating high severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote over HTTP, exploiting an authenticated session. Given the lack of permission checks on PUT operations, an attacker can gain unauthorized modification rights, posing a significant risk to configuration integrity.
OpenCVE Enrichment