Executive brief
JetBrains YouTrack is a project tracking and issue management system used by software development teams. A vulnerability in the predefined search fields feature allowed unauthorized disclosure of all group names to any user, even those without permission to view specific groups. This could allow a user to discover the existence and names of confidential group structures within an organization.
Technical details
An information disclosure vulnerability in JetBrains YouTrack before version 2026.1.14047 failed to properly enforce group visibility permissions when displaying predefined search field values. The vulnerable component (predefined search fields) exposed group names regardless of the requesting user's visibility permissions. The vulnerability is reachable by any authenticated user without additional preconditions. An attacker can enumerate and discover all group names in the system, which may reveal sensitive organizational structure. The issue has been patched in YouTrack 2026.1.14047 and later.
Affected products
- JetBrains YouTrack before 2026.1.14047
Timeline
- 2026-09-07: disclosed