Executive brief
JetBrains YouTrack is an issue tracking and project management platform used by development teams. A flaw in the generic VCS webhook handler allows authentication to be bypassed when no secret is configured, potentially enabling unauthorized trigger of webhook events and integration manipulation.
Technical details
The vulnerability is an authentication bypass in the generic VCS webhook handler in JetBrains YouTrack. When the webhook secret is left blank or unconfigured, the handler fails to properly validate incoming webhook requests, allowing unauthenticated requests to be processed. This affects versions before 2026.2.18634. An attacker with network access to the YouTrack instance can send crafted webhook requests to trigger automated workflows or inject malicious data into the system without proper authorization. The issue is patched in YouTrack 2026.2.18634 and later.
Affected products
- JetBrains YouTrack before 2026.2.18634
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fixed in version 2026.2.18634