Executive brief
YouTrack is an issue-tracking and project management system used by teams to organize work and collaborate on projects. A flaw in the user profile API allowed attackers to access private issues and starred project folders belonging to other users across different organizations without authorization. This could expose sensitive project details, roadmaps, and internal issue discussions to unauthorized parties.
Technical details
This vulnerability is an Insecure Direct Object Reference (IDOR) in the user profile API endpoint. The API failed to properly validate authorization checks when accessing profile data, allowing attackers to enumerate and retrieve private issues and starred folder metadata for arbitrary users by manipulating request parameters. The vulnerability affects YouTrack versions before 2026.2.18634 and requires network access to the YouTrack instance but does not appear to require authentication or special preconditions beyond basic API access. An attacker could discover sensitive project information, private issue contents, and organizational structure details across multiple organizations. The issue has been patched in version 2026.2.18634 and later.
Affected products
- JetBrains YouTrack before 2026.2.18634
Timeline
- 2026-09-07: disclosed