Junglewise Threat Intelligence

CVE-2026-75045: JetBrains YouTrack unauthenticated database backup download

CVE-2026-75045 · Severity: critical · CVSS 9.1 · Published 2026-08-17

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

YouTrack is JetBrains' issue and project tracking system used by development teams to manage software development workflows. An unauthenticated attacker could bypass access controls and download complete database backups through a vulnerability in the shared draft signature mechanism, potentially exposing all project data, user credentials, and sensitive organizational information stored in YouTrack instances.

Technical details

The vulnerability is an authentication bypass in YouTrack's backup download functionality, exploitable through a weakness in shared draft signature validation. An unauthenticated attacker can craft requests using the shared draft signature mechanism to download database backups without providing valid credentials or authentication tokens. The attack requires network access to the YouTrack instance and no user interaction. Successful exploitation allows complete unauthorized access to database backups containing all stored data. The vulnerability is fixed in YouTrack versions 2025.3.156085, 2026.1.13913, and 2026.2.18112 or later.

Affected products

  • JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112

Timeline

  • 2026-08-17: disclosed

References

Related threats