Executive brief
JetBrains YouTrack is a project management and issue tracking system. A vulnerability in the whiteboard feature allowed users with read-only access to modify canvas content through crafted WebSocket messages, bypassing intended access controls and potentially corrupting or tampering with shared project work.
Technical details
This vulnerability is a privilege escalation / access control bypass in YouTrack's whiteboard WebSocket handling. Read-only whiteboard users could craft malicious WebSocket messages to modify canvas content that should have been restricted. The vulnerability requires network access to YouTrack and an authenticated session as a read-only whiteboard user. A successful exploit allows an attacker with limited permissions to modify collaborative whiteboard content, violating access control policies. The issue is fixed in YouTrack version 2026.2.18634 and later.
Affected products
- JetBrains YouTrack before 2026.2.18634
Timeline
- 2026-09-07: disclosed