Junglewise Threat Intelligence

CVE-2026-57923: JetBrains YouTrack improper authorization in app configurations endpoint

CVE-2026-57923 · Severity: medium · CVSS 5.3 · Published 2026-06-26

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack, a project management and issue tracking tool, contained a security flaw in its configuration settings. An authorized user with low-level access could bypass security checks to modify project settings they should not have permission to change. This could lead to unauthorized changes in project workflows or configurations, potentially disrupting team operations.

Technical details

An improper authorization vulnerability (CWE-862) exists in JetBrains YouTrack versions prior to 2026.2.16593. The flaw is located within the app configurations endpoint, where insufficient permission checks allow an authenticated user with low privileges to modify project-level settings. The attack requires network access and valid user credentials, though the complexity is rated as high, likely due to specific configuration requirements or the need for precise API requests. Successful exploitation allows an attacker to compromise the integrity of project configurations without affecting data confidentiality or service availability. The issue has been addressed in version 2026.2.16593.

Affected products

  • JetBrains YouTrack before 2026.2.16593

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory

References

Related threats