Impact
The vulnerability arises from a missing escalation check in JetBrains YouTrack versions prior to 2026.1.14047. This flaw allows a user who already has permission to update projects to elevate their role to Project Admin. The elevated role grants full administrative control over the entire YouTrack instance, enabling the user to modify any project, change settings, create and delete users, and potentially alter or delete data. Consequently, confidentiality, integrity, and availability of the system may be compromised.
Affected Systems
The affected product is JetBrains YouTrack. Versions earlier than 2026.1.14047 are vulnerable. The vulnerability does not affect newer releases that include the mitigation.
Risk and Exploitability
The score of 5.5 indicates medium severity; the EPSS value is not available, and the vulnerability has not been listed in CISA's KEV catalog, suggesting no widespread exploitation has been observed. Because the flaw requires a user to already have project update permissions, the likely attack vector is internal or from a compromised account. Based on the provided metrics, the exploitation likelihood appears moderate, but the impact if successful is significant due to the elevation to full administrative rights.
OpenCVE Enrichment