Junglewise Threat Intelligence

CVE-2026-57921: JetBrains YouTrack improper access control in comment templates

CVE-2026-57921 · Severity: medium · CVSS 4.3 · Published 2026-06-26

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack, a project management and issue tracking tool, contained a security flaw that allowed users to view private information belonging to others. By accessing a specific feature used for managing comment templates, an authenticated user could bypass normal security checks to read sensitive data. This could lead to the unauthorized disclosure of private user details within the organization.

Technical details

An improper access control vulnerability (CWE-862) exists in JetBrains YouTrack versions prior to 2026.2.16593. The flaw is located within the comment templates API endpoint, which failed to correctly enforce authorization checks. A remote attacker with low-privileged authenticated access could exploit this by sending crafted requests to the endpoint to retrieve private data belonging to other users. The vulnerability is restricted to information disclosure (Confidentiality: Low) and does not allow for data modification or service disruption. The issue has been resolved in version 2026.2.16593.

Affected products

  • JetBrains YouTrack before 2026.2.16593

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory

References

Related threats