Executive brief
JetBrains YouTrack Helpdesk is a customer support platform used by organizations to manage service requests and customer interactions. A flaw in its authentication mechanism allowed attackers to take over user accounts by self-asserting an email address without proper verification, enabling unauthorized access to customer data and support systems without requiring valid credentials.
Technical details
The vulnerability exists in YouTrack Helpdesk's authentication logic, where improper validation of email-based identity allowed attackers to claim and register arbitrary email addresses without verification. The flaw enables unauthenticated account takeover through self-asserted email identity, meaning no prior authentication or valid credentials are required—an attacker can directly register or take over an account associated with any email address. The attack is network-accessible and requires no special preconditions beyond network reachability. This allows full account compromise and access to customer support data, tickets, and potentially sensitive organizational information. The vulnerability was fixed in versions 2025.3.161254 and 2026.1.14042.
Affected products
- JetBrains YouTrack Helpdesk before 2025.3.161254, before 2026.1.14042
Timeline
- 2026-09-07: disclosed
- 2026-01-14: patched: Fixed in version 2026.1.14042
- 2025-03-16: patched: Fixed in version 2025.3.161254