Executive brief
YouTrack is a web-based issue tracking and project management system used by development teams. A flaw in permission checks allows users with basic project update permissions to escalate their own access to Project Administrator level without proper authorization, potentially giving them control over project settings, user access, and data.
Technical details
YouTrack contains an authorization bypass vulnerability where a missing escalation check in the permission model allows privilege escalation. A user authenticated with project update permissions can exploit this flaw to grant themselves Project Administrator role. The vulnerability requires the attacker to already hold update permissions on a project, but does not require additional user interaction. The flaw was patched in version 2026.1.14047 and later.
Affected products
- JetBrains YouTrack before 2026.1.14047
Timeline
- 2026-09-07: disclosed
- 2026-01: patched: Fixed in version 2026.1.14047