Executive brief
JetBrains YouTrack, a project management and issue tracking tool, contained a security flaw that allowed users with low-level permissions to modify service accounts. This could allow an internal user to alter automated system integrations or service configurations, potentially disrupting business workflows or escalating their influence within the platform. The issue has been resolved in version 2026.1.13570.
Technical details
An improper access control vulnerability (CWE-862: Missing Authorization) in JetBrains YouTrack prior to version 2026.1.13570 allowed authenticated users with low privileges to modify service accounts. The vulnerability is exploitable over the network without user interaction, provided the attacker has a valid account on the system. By manipulating service account configurations, an attacker could impact the integrity of system integrations. The vendor has addressed this issue in the 2026.1.13570 release.
Affected products
- JetBrains YouTrack before 2026.1.13570
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory