Executive brief
JetBrains YouTrack, a project management and issue tracking tool, contained a configuration flaw in its default user roles. This flaw allowed authenticated users to view more profile information about other users than intended. While this does not allow for full account takeover, it could lead to the exposure of sensitive employee or collaborator details.
Technical details
A vulnerability classified as Incorrect Default Permissions (CWE-276) exists in JetBrains YouTrack versions prior to 2026.2.16593. The default role configuration was overly permissive, allowing authenticated users (PR:L) to access excessive profile details of other users via the network. This is a confidentiality-only issue with a CVSS score of 4.3. The issue has been addressed in version 2026.2.16593.
Affected products
- JetBrains YouTrack before 2026.2.16593
Timeline
- 2026-06-26: disclosed
- 2026-06-26: patched: Fixed in version 2026.2.16593