Executive brief
JetBrains YouTrack is a project management and issue tracking system used by development teams. A missing permission check allowed users to create knowledge base articles in projects they should not have access to, potentially exposing internal information or allowing unauthorized modifications to shared documentation.
Technical details
The vulnerability is a missing permission check in the knowledge base article creation endpoint. Users could bypass project access controls and create articles in projects where they lack proper permissions, due to inadequate authorization validation before article creation. This is an authorization bypass vulnerability reachable by authenticated users with YouTrack access. An attacker with valid credentials could create and potentially modify knowledge base content in restricted projects. The vulnerability is fixed in YouTrack 2026.2.18687 and later.
Affected products
- JetBrains YouTrack before 2026.2.18687
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fixed in YouTrack 2026.2.18687