Impact
JetBrains YouTrack versions prior to 2026.1.14047 contain a missing authorization flaw that causes predefined search fields to expose every group name in the system. The vulnerability does not modify or delete data; its primary impact is the disclosure of potentially sensitive group membership information which could be used by an attacker to map internal structures, facilitate social engineering, or plan further attacks. This flaw is identified as CWE-862, a missing authorization weakness.
Affected Systems
Users of JetBrains YouTrack installations running any version earlier than 2026.1.14047 are affected. The issue applies to all users who can view predefined search fields, regardless of their group visibility permissions. No additional product or vendor versions are listed.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate impact, and the EPSS score is unavailable, so the current likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation at this time. Based on the description, it is inferred that the likely attack vector is accessing the UI or API with authenticated access, which can trigger the information leak by querying predefined search fields.
OpenCVE Enrichment