Executive brief
JetBrains YouTrack is a popular project management and issue-tracking platform used by development teams. This vulnerability allows attackers to bypass authorization controls and access restricted API resources without proper authentication, potentially exposing sensitive project data, user information, and internal communications.
Technical details
The vulnerability is an authorization bypass (IDOR – Insecure Direct Object Reference) in YouTrack's REST API that allows unauthenticated or low-privileged attackers to access restricted resources. The root cause is missing or insufficient authorization checks on API endpoints. An attacker can directly request sensitive resources without proper credentials. Affected versions include YouTrack 2026.2 before 18788, 2026.1 before 14055, and 2025.3 before 161254. The vulnerability is network-accessible and requires no user interaction. Patches are available in the fixed versions listed above.
Affected products
- JetBrains YouTrack before 2026.2.18788, before 2026.1.14055, before 2025.3.161254
Timeline
- 2026-09-07: disclosed