Junglewise Threat Intelligence

CVE-2026-49385: JetBrains YouTrack improper access control in service accounts

CVE-2026-49385 · Severity: medium · CVSS 6.5 · Published 2026-05-29

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack, a project management and issue tracking tool, contained a security flaw that allowed users with low-level permissions to modify service accounts. This could allow an internal user to alter automated system integrations or service configurations, potentially disrupting business workflows or escalating their influence within the platform. The issue has been resolved in version 2026.1.13570.

Technical details

An improper access control vulnerability (CWE-862: Missing Authorization) in JetBrains YouTrack prior to version 2026.1.13570 allowed authenticated users with low privileges to modify service accounts. The vulnerability is exploitable over the network without user interaction, provided the attacker has a valid account on the system. By manipulating service account configurations, an attacker could impact the integrity of system integrations. The vendor has addressed this issue in the 2026.1.13570 release.

Affected products

  • JetBrains YouTrack before 2026.1.13570

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory

References

Related threats