Junglewise Threat Intelligence

CVE-2026-49369: JetBrains YouTrack information disclosure in Users and Groups pages

CVE-2026-49369 · Severity: medium · CVSS 4.3 · Published 2026-05-29

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack, a project management and issue tracking tool, contained a vulnerability that allowed unauthorized access to sensitive information. An authenticated user could view details on the Users and Groups pages that they should not have been able to see. This could lead to the exposure of internal organizational structures or user details, potentially aiding further targeted attacks.

Technical details

An information disclosure vulnerability exists in JetBrains YouTrack versions prior to 2026.1.13162 due to incorrect authorization (CWE-863) on the Users and Groups management pages. A remote attacker with low-privileged authenticated access can exploit this flaw to view sensitive information that should be restricted to administrators. The attack is carried out over the network without requiring user interaction. The issue has been addressed in version 2026.1.13162.

Affected products

  • JetBrains YouTrack before 2026.1.13162

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory

References

Related threats