Junglewise Threat Intelligence

CVE-2026-57922: JetBrains YouTrack project settings disclosure in MCP

CVE-2026-57922 · Severity: low · CVSS 3.1 · Published 2026-06-26

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack, a project management and issue tracking tool, was found to have a vulnerability that could allow unauthorized users to view project settings. An attacker with low-level access could potentially see configuration details they are not supposed to access. This issue has been resolved in version 2026.2.16593.

Technical details

A missing authorization vulnerability (CWE-862) in JetBrains YouTrack before version 2026.2.16593 allowed the disclosure of project settings via the Model Context Protocol (MCP). The vulnerability requires an attacker to have network access and at least low-level authenticated privileges. The attack complexity is considered high, likely due to specific requirements in how the MCP must be interacted with to leak the settings. Successful exploitation results in a loss of confidentiality regarding project configuration. The issue is fixed in YouTrack version 2026.2.16593.

Affected products

  • JetBrains YouTrack before 2026.2.16593

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory

References

Related threats