Junglewise Threat Intelligence

CVE-2026-57925: JetBrains YouTrack improper access control in saved queries and tags

CVE-2026-57925 · Severity: medium · CVSS 4.3 · Published 2026-06-26

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack, a project management and issue tracking tool, contained a security flaw that allowed users to view saved search queries and tags they were not authorized to see. While this does not allow for the modification of data or system takeover, it could lead to the exposure of sensitive internal project organization or naming conventions. Organizations using YouTrack should update to version 2026.2.16593 or later to resolve this issue.

Technical details

An improper access control vulnerability (CWE-862: Missing Authorization) exists in JetBrains YouTrack versions prior to 2026.2.16593. The flaw allows an authenticated user with low privileges to bypass intended access restrictions and read saved queries and tags belonging to other users or projects. The attack can be carried out over the network without user interaction. The impact is limited to unauthorized information disclosure (confidentiality), with no impact on data integrity or system availability. The issue is resolved in version 2026.2.16593.

Affected products

  • JetBrains YouTrack before 2026.2.16593

Timeline

  • 2026-06-26: advisory: Initial disclosure by JetBrains and NVD publication.
  • 2026-06-26: patched: Fix available in version 2026.2.16593.

References

Related threats