Executive brief
JetBrains YouTrack, a project management and issue tracking tool, was found to have a security flaw that could lead to unauthorized information disclosure. An attacker with high-level privileges could potentially access sensitive data through specific application requests. This could result in the exposure of internal configuration or metadata, though the overall impact is considered low.
Technical details
An information disclosure vulnerability exists in JetBrains YouTrack versions prior to 2026.1.13162. The flaw is categorized as CWE-201 (Insertion of Sensitive Information Into Sent Data) and occurs during 'fetchApp' requests. An attacker with high privileges (PR:H) can exploit this over the network, though it requires some level of user interaction (UI:R). Successful exploitation allows the attacker to read sensitive information that should not have been transmitted, potentially leading to further reconnaissance. The issue has been addressed in version 2026.1.13162.
Affected products
- JetBrains YouTrack before 2026.1.13162
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory