Junglewise Threat Intelligence

CVE-2026-49386: JetBrains YouTrack improper access control in Planning Canvas

CVE-2026-49386 · Severity: medium · CVSS 6.5 · Published 2026-05-29

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack, a project management and issue tracking tool, contained a security flaw in its Planning Canvas feature. This vulnerability allowed authenticated users to view the titles or details of restricted issues and articles they should not have had permission to see. This could lead to the exposure of sensitive project information or internal documentation to unauthorized personnel.

Technical details

An improper access control vulnerability (CWE-639) exists in JetBrains YouTrack versions prior to 2026.1.13570. The flaw is located within the Planning Canvas component, where insufficient authorization checks allowed an authenticated attacker to enumerate and potentially view restricted issues and articles. The attack vector is network-based and requires low privileges, but no user interaction. By manipulating user-controlled keys or parameters, an attacker could bypass intended visibility restrictions. The issue has been addressed in version 2026.1.13570.

Affected products

  • JetBrains YouTrack before 2026.1.13570

Timeline

  • 2026-05-29: advisory: CVE published by JetBrains s.r.o.
  • 2026-05-29: patched: Fix available in version 2026.1.13570

References

Related threats