Junglewise Threat Intelligence

CVE-2026-75044: JetBrains YouTrack missing authorization in mailbox endpoint

CVE-2026-75044 · Severity: high · CVSS 8.1 · Published 2026-08-17

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a project management and issue tracking system used by development teams to plan and track work. An authentication bypass flaw allows authenticated users to delete arbitrary data through the mailbox endpoint, potentially causing data loss and disruption to project management operations.

Technical details

The vulnerability is a missing authorization (insecure direct object reference / IDOR) flaw in the YouTrack mailbox endpoint. An authenticated user can bypass authorization checks to delete arbitrary entities beyond their intended permissions. The attack requires valid authentication credentials but does not require additional user interaction or network-level access beyond standard HTTP requests. An attacker can cause data loss and operational disruption by deleting critical project data. Patches are available in YouTrack versions 2025.3.156085, 2026.1.13914, and 2026.2.18095 or later.

Affected products

  • JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: patched: Fixes available in versions 2025.3.156085, 2026.1.13914, 2026.2.18095

References

Related threats