Executive brief
JetBrains YouTrack is a project tracking and issue management system used by development teams. A flaw in its GitHub integration allowed attackers on one tenant (customer instance) to steal GitHub App installation tokens from other tenants, potentially granting unauthorized access to repositories and sensitive source code across multiple organizations.
Technical details
YouTrack uses a shared token cache for GitHub App installation tokens without proper tenant isolation. An attacker with access to one YouTrack tenant instance could retrieve cached tokens belonging to other tenants, bypassing authentication and authorization controls. The vulnerability affects YouTrack versions before 2026.2.18634. This is a cross-tenant data exposure issue resulting from insufficient cache compartmentalization. The issue has been patched in version 2026.2.18634 and later.
Affected products
- JetBrains YouTrack before 2026.2.18634
Timeline
- 2026-09-07: disclosed
- 2026-02-18: patched: Fixed in YouTrack 2026.2.18634 and later