Executive brief
JetBrains YouTrack is a project management and issue tracking system used by development teams to plan and track work. An authentication bypass flaw allows authenticated users to delete arbitrary data through the mailbox endpoint, potentially causing data loss and disruption to project management operations.
Technical details
The vulnerability is a missing authorization (insecure direct object reference / IDOR) flaw in the YouTrack mailbox endpoint. An authenticated user can bypass authorization checks to delete arbitrary entities beyond their intended permissions. The attack requires valid authentication credentials but does not require additional user interaction or network-level access beyond standard HTTP requests. An attacker can cause data loss and operational disruption by deleting critical project data. Patches are available in YouTrack versions 2025.3.156085, 2026.1.13914, and 2026.2.18095 or later.
Affected products
- JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095
Timeline
- 2026-08-17: disclosed
- 2026-08-17: patched: Fixes available in versions 2025.3.156085, 2026.1.13914, 2026.2.18095