Executive brief
YouTrack is JetBrains' issue tracking and project management platform used by development teams to manage work and collaborate. An authenticated user could bypass access controls to read restricted articles and documentation from projects they should not have access to, potentially exposing sensitive project information, architectural details, or internal documentation to unauthorized team members.
Technical details
This is an access control vulnerability in the draft creation endpoint of YouTrack. An authenticated user can exploit improper authorization checks in the draft creation functionality to read restricted articles from projects outside their assigned permissions. The vulnerability affects YouTrack versions before 2026.1.13903 and 2026.2.17950. Attack requires valid authentication credentials. The fix is available in the patched versions mentioned.
Affected products
- JetBrains YouTrack before 2026.1.13903 and 2026.2.17950
Timeline
- 2026-08-17: disclosed