Junglewise Threat Intelligence

CVE-2026-75051: JetBrains YouTrack unauthorised project transfer between organisations

CVE-2026-75051 · Severity: high · CVSS 8.1 · Published 2026-08-17

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a project and issue tracking system used by development teams to manage work and collaboration. This vulnerability allowed unauthorised users to transfer projects between different organisations without proper access controls, potentially exposing sensitive project data to unauthorised teams and compromising data isolation between tenants.

Technical details

YouTrack before version 2026.2.17917 suffered from an access control vulnerability that failed to properly validate whether a user had permission to transfer projects across organisation boundaries. The vulnerability likely stems from insufficient authorization checks in the project transfer functionality. An authenticated attacker could exploit this by invoking project transfer operations to move sensitive projects to organisations they control or have access to, bypassing multi-tenancy isolation. The issue has been patched in YouTrack 2026.2.17917 and later versions.

Affected products

  • JetBrains YouTrack before 2026.2.17917

Timeline

  • 2026-08-17: disclosed
  • 2026-02: patched: Fixed in YouTrack 2026.2.17917

References

Related threats