Executive brief
JetBrains YouTrack, a project management and issue tracking tool, was found to have a vulnerability that could allow unauthorized users to view project settings. An attacker with low-level access could potentially see configuration details they are not supposed to access. This issue has been resolved in version 2026.2.16593.
Technical details
A missing authorization vulnerability (CWE-862) in JetBrains YouTrack before version 2026.2.16593 allowed the disclosure of project settings via the Model Context Protocol (MCP). The vulnerability requires an attacker to have network access and at least low-level authenticated privileges. The attack complexity is considered high, likely due to specific requirements in how the MCP must be interacted with to leak the settings. Successful exploitation results in a loss of confidentiality regarding project configuration. The issue is fixed in YouTrack version 2026.2.16593.
Affected products
- JetBrains YouTrack before 2026.2.16593
Timeline
- 2026-06-26: disclosed
- 2026-06-26: advisory