Junglewise Threat Intelligence

CVE-2026-75046: JetBrains YouTrack user enumeration in search endpoint

CVE-2026-75046 · Severity: medium · CVSS 4.3 · Published 2026-08-17

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is an issue tracking and project management platform used by development teams. An authenticated user could exploit a flaw in the user search endpoint to enumerate all accounts in the system, potentially revealing the organizational structure and identifying targets for further attack.

Technical details

The vulnerability is an account enumeration issue in the users search endpoint of JetBrains YouTrack. An authenticated attacker can query the endpoint to systematically discover valid user accounts without proper rate limiting or access controls. The attack requires authentication but allows an attacker to extract a complete or partial list of organizational users. The vulnerability is fixed in YouTrack version 2026.2.18112 and later.

Affected products

  • JetBrains YouTrack before 2026.2.18112

Timeline

  • 2026-08-17: disclosed
  • 2026-2.181: patched

References

Related threats