Junglewise Threat Intelligence

CVE-2026-49370: JetBrains YouTrack information disclosure in fetchApp requests

CVE-2026-49370 · Severity: low · CVSS 3.4 · Published 2026-05-29

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack, a project management and issue tracking tool, was found to have a security flaw that could lead to unauthorized information disclosure. An attacker with high-level privileges could potentially access sensitive data through specific application requests. This could result in the exposure of internal configuration or metadata, though the overall impact is considered low.

Technical details

An information disclosure vulnerability exists in JetBrains YouTrack versions prior to 2026.1.13162. The flaw is categorized as CWE-201 (Insertion of Sensitive Information Into Sent Data) and occurs during 'fetchApp' requests. An attacker with high privileges (PR:H) can exploit this over the network, though it requires some level of user interaction (UI:R). Successful exploitation allows the attacker to read sensitive information that should not have been transmitted, potentially leading to further reconnaissance. The issue has been addressed in version 2026.1.13162.

Affected products

  • JetBrains YouTrack before 2026.1.13162

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory

References

Related threats