JetBrains Youtrack
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in JetBrains Youtrack.
By the Year
In 2026 there have been 47 vulnerabilities in JetBrains Youtrack with an average score of 6.0 out of ten. Last year, in 2025 Youtrack had 15 security vulnerabilities published. That is, 32 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.29.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 47 | 6.01 |
| 2025 | 15 | 5.72 |
| 2024 | 28 | 6.09 |
| 2023 | 4 | 6.13 |
| 2022 | 7 | 5.87 |
| 2021 | 21 | 6.56 |
| 2020 | 18 | 6.04 |
| 2019 | 11 | 6.10 |
It may take a day or so for new Youtrack vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent JetBrains Youtrack Security Vulnerabilities
JetBrains YouTrack <2026.1.14047: Escalation Check Bypass Grants Admin
CVE-2026-86500
5.5 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin
Incorrect Privilege Assignment
YouTrack pre-2026.1.14047: Predefined search fields leak group names
CVE-2026-86499
4.3 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
AuthZ
YouTrack <2025.3.160480: Unauthorized PUT on Link Sub-Resources
CVE-2026-86498
7.7 - High
- September 07, 2026
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
AuthZ
YouTrack <=2026.2.18769 Credential Exfiltration via Mailbox Host Change
CVE-2026-86497
6.8 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
Insertion of Sensitive Information Into Sent Data
JetBrains YouTrack <2026.2.18769: Helpdesk Reporter Email Exposure
CVE-2026-86496
4.3 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses
AuthZ
JetBrains YouTrack < 2026.2.18687 Missing Permission Checks for KB Articles
CVE-2026-86495
6.5 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects
AuthZ
YouTrack <2026.2.18634: Whiteboard clone allows unauthorized link changes
CVE-2026-86494
7.7 - High
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
AuthZ
YouTrack < 2026.2.18634 Checks Let Read-Only Users Modify Whiteboard Cards
CVE-2026-86493
6.5 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards
AuthZ
YouTrack < 2026.2.18634 Cross-Tenant GitHub App Token Theft via Shared Cache
CVE-2026-86492
8.5 - High
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
Exposure of Data Element to Wrong Session
YouTrack XSS via Project/Org Icon Uploads (pre2026.2.18634)
CVE-2026-86491
3.5 - Low
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads
XSS
YouTrack <2026.2.18634 Improper Permission Checks Overwrite Bundled Apps
CVE-2026-86490
6.5 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint
AuthZ
JetBrains YouTrack IDOR in User Profile API before 2026.2.18634
CVE-2026-86489
6.5 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations
Insecure Direct Object Reference / IDOR
JetBrains YouTrack <2026.2.18634 iDOR via watchRules & issueListConfig
CVE-2026-86488
6.5 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches
Insecure Direct Object Reference / IDOR
YouTrack WebSocket Canvas Injection before 2026.2.18634
CVE-2026-86487
3.1 - Low
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content
AuthZ
YouTrack VCS Webhook Handler Allows Open Access with Blank Secret <2026.2.18634
CVE-2026-86486
3.7 - Low
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank
Missing Authentication for Critical Function
JetBrains YouTrack <2026.2.18634: IP Spoofing via Headers Bitbucket Webhooks
CVE-2026-86485
3.5 - Low
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks
Reliance on IP Address for Authentication
YouTrack <2026.2.18634 AngularJS Template Injection XSS
CVE-2026-86484
4.6 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
XSS
JetBrains YouTrack XSS via Agile Board Custom Field (< 2026.2.18634)
CVE-2026-86483
5.4 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
XSS
JetBrains YouTrack < 2026.2.18634 PrivEsc via Unchecked Group Membership
CVE-2026-86482
8.8 - High
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
Incorrect Privilege Assignment
JetBrains YouTrack 2026.2.18634 Signed URL Reuse Disclosure
CVE-2026-86481
4.3 - Medium
- September 07, 2026
In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
Insecure Direct Object Reference / IDOR
JetBrains YouTrack 2026.2.18788 IDOR: Unauthorized REST API Access
CVE-2026-86479
8 - High
- September 07, 2026
In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
AuthZ
YouTrack <2025.3.161254 & 2026.1.14042 Unauth Takeover
CVE-2026-86478
9.8 - Critical
- September 07, 2026
In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address
Authentication Bypass by Spoofing
YouTrack 2026.2.17917: Unauthorized Project Transfer Between Orgs
CVE-2026-75051
8.1 - High
- August 17, 2026
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
AuthZ
YouTrack DoS via crafted type params in <2026.1.13901 & 2026.2.17950
CVE-2026-75050
7.1 - High
- August 17, 2026
In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
Allocation of Resources Without Limits or Throttling
YouTrack Auth Read Rstrctd Articles via Draft-Create EP (v1.13903/v2.17950)
CVE-2026-75049
6.5 - Medium
- August 17, 2026
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
AuthZ
JetBrains YouTrack <2026.2.18068 XSS via Code Label
CVE-2026-75048
8.2 - High
- August 17, 2026
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
XSS
JetBrains YouTrack DoS via decompression bomb (pre-2026.2.18177)
CVE-2026-75047
6.5 - Medium
- August 17, 2026
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
Data Amplification
YouTrack <=2026.2.18112: Auth User Enum via Search (CVE-2026-75046)
CVE-2026-75046
4.3 - Medium
- August 17, 2026
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
AuthZ
JetBrains YouTrack < 2025.3.156085, 2026.x: Unauth DB backup via draft sig
CVE-2026-75045
9.1 - Critical
- August 17, 2026
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
Authentication Bypass Using an Alternate Path or Channel
JetBrains YouTrack 2026.2.18095: Auth Deletion via Mailbox Endpt
CVE-2026-75044
8.1 - High
- August 17, 2026
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
AuthZ
Auth Bypass in JetBrains YouTrack <2026.1.13757 via Direct DB Access
CVE-2026-62422
10 - Critical
- July 14, 2026
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
Missing Authentication for Critical Function
JetBrains YouTrack XSS via article title in digest email before 2026.2.17394
CVE-2026-61492
3.5 - Low
- July 10, 2026
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
XSS
YouTrack <2026.2.17012: CSS Injection via Mermaid Diagram
CVE-2026-59791
3.5 - Low
- July 10, 2026
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
Clickjacking
Prototype Pollution in JetBrains YouTrack before 2026.2.16593 Websandbox Bridge
CVE-2026-57926
2.6 - Low
- June 26, 2026
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
Prototype Pollution
YouTrack <=2026.2.16593 Default Role Config Exposes User Profile Details
CVE-2026-57924
4.3 - Medium
- June 26, 2026
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
Incorrect Default Permissions
YouTrack <2026.2.16593 Improper Access Control Read Queries & Tags
CVE-2026-57925
4.3 - Medium
- June 26, 2026
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
AuthZ
YouTrack <2026.2.16593 Improper Auth on App Config Endpoint
CVE-2026-57923
5.3 - Medium
- June 26, 2026
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
AuthZ
JetBrains YouTrack 2026.2.16593 Project Settings Disclosure via MCP
CVE-2026-57922
3.1 - Low
- June 26, 2026
In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
AuthZ
YouTrack <2026.2.16593 Improper Access: Read Private Data via Comment Templates
CVE-2026-57921
4.3 - Medium
- June 26, 2026
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
AuthZ
Improper Access Control in JetBrains YouTrack <2026.1.13570 (Planning Canvas)
CVE-2026-49386
6.5 - Medium
- May 29, 2026
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
Insecure Direct Object Reference / IDOR
YouTrack <2026.1.13570 Improper ACL: Low-Privileged Modifies Service Accounts
CVE-2026-49385
6.5 - Medium
- May 29, 2026
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
AuthZ
Stored XSS in YouTrack Notification Templates before 2026.1.13162
CVE-2026-49368
8.7 - High
- May 29, 2026
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
XSS
YouTrack Info Disclosure before 2026.1.13162 on Users/Groups
CVE-2026-49369
4.3 - Medium
- May 29, 2026
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
AuthZ
YouTrack 2026.1.13162 Info Disclosure via fetchApp
CVE-2026-49370
3.4 - Low
- May 29, 2026
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
Insertion of Sensitive Information Into Sent Data
YouTrack 2025.3.131383 RCE via Sandbox Bypass (JetBrains)
CVE-2026-33392
7.2 - High
- April 17, 2026
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
1336
JetBrains YouTrack < 2025.3.121962 AuthBreach via perms endpoint
CVE-2026-28193
8.8 - High
- February 25, 2026
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
AuthZ
JetBrains YouTrack <2025.3.119033 access tokens exposed in mailbox logs
CVE-2026-25846
6.5 - Medium
- February 09, 2026
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
Insertion of Sensitive Information into Log File
YouTrack <2025.3.104432 Race Condition Bypass Helpdesk Agent Limit
CVE-2025-64773
2.7 - Low
- November 11, 2025
In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit
Race Condition
JetBrains YouTrack <2025.3.104432 insecure Junie config: data exfil + auth chg
CVE-2025-64690
- November 10, 2025
YouTrack <=2025.3.104432 Junie Token Leak via Misconfig
CVE-2025-64689
- November 10, 2025
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for JetBrains Youtrack or by JetBrains? Click the Watch button to subscribe.