Executive brief
JetBrains YouTrack is a project management and issue tracking system used by development teams. A flaw in permission checks allowed read-only users to create and modify whiteboard cards despite lacking the necessary privileges, potentially enabling unauthorized changes to project documentation and collaborative content that should have been restricted to users with higher access levels.
Technical details
The vulnerability is a privilege escalation resulting from improper permission validation in YouTrack's whiteboard card functionality. Read-only users could bypass permission checks to create and modify whiteboard cards, actions that should have been restricted to users with appropriate write permissions. The attack requires network access to a YouTrack instance but does not require elevated authentication—any read-only user can exploit it. An attacker can create arbitrary whiteboard content and modify existing cards, potentially compromising data integrity and project planning information. The issue is fixed in YouTrack 2026.2.18634 and later versions.
Affected products
- JetBrains YouTrack before 2026.2.18634
Timeline
- 2026-09-07: disclosed