Youtrack JetBrains Youtrack

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in JetBrains Youtrack.

By the Year

In 2026 there have been 47 vulnerabilities in JetBrains Youtrack with an average score of 6.0 out of ten. Last year, in 2025 Youtrack had 15 security vulnerabilities published. That is, 32 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.29.




Year Vulnerabilities Average Score
2026 47 6.01
2025 15 5.72
2024 28 6.09
2023 4 6.13
2022 7 5.87
2021 21 6.56
2020 18 6.04
2019 11 6.10

It may take a day or so for new Youtrack vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent JetBrains Youtrack Security Vulnerabilities

JetBrains YouTrack <2026.1.14047: Escalation Check Bypass Grants Admin
CVE-2026-86500 5.5 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin

Incorrect Privilege Assignment

YouTrack pre-2026.1.14047: Predefined search fields leak group names
CVE-2026-86499 4.3 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission

AuthZ

YouTrack <2025.3.160480: Unauthorized PUT on Link Sub-Resources
CVE-2026-86498 7.7 - High - September 07, 2026

In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

AuthZ

YouTrack <=2026.2.18769 Credential Exfiltration via Mailbox Host Change
CVE-2026-86497 6.8 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials

Insertion of Sensitive Information Into Sent Data

JetBrains YouTrack <2026.2.18769: Helpdesk Reporter Email Exposure
CVE-2026-86496 4.3 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses

AuthZ

JetBrains YouTrack < 2026.2.18687 Missing Permission Checks for KB Articles
CVE-2026-86495 6.5 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects

AuthZ

YouTrack <2026.2.18634: Whiteboard clone allows unauthorized link changes
CVE-2026-86494 7.7 - High - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues

AuthZ

YouTrack < 2026.2.18634 Checks Let Read-Only Users Modify Whiteboard Cards
CVE-2026-86493 6.5 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards

AuthZ

YouTrack < 2026.2.18634 Cross-Tenant GitHub App Token Theft via Shared Cache
CVE-2026-86492 8.5 - High - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

Exposure of Data Element to Wrong Session

YouTrack XSS via Project/Org Icon Uploads (pre2026.2.18634)
CVE-2026-86491 3.5 - Low - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads

XSS

YouTrack <2026.2.18634 Improper Permission Checks Overwrite Bundled Apps
CVE-2026-86490 6.5 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint

AuthZ

JetBrains YouTrack IDOR in User Profile API before 2026.2.18634
CVE-2026-86489 6.5 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations

Insecure Direct Object Reference / IDOR

JetBrains YouTrack <2026.2.18634 iDOR via watchRules & issueListConfig
CVE-2026-86488 6.5 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches

Insecure Direct Object Reference / IDOR

YouTrack WebSocket Canvas Injection before 2026.2.18634
CVE-2026-86487 3.1 - Low - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content

AuthZ

YouTrack VCS Webhook Handler Allows Open Access with Blank Secret <2026.2.18634
CVE-2026-86486 3.7 - Low - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank

Missing Authentication for Critical Function

JetBrains YouTrack <2026.2.18634: IP Spoofing via Headers Bitbucket Webhooks
CVE-2026-86485 3.5 - Low - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks

Reliance on IP Address for Authentication

YouTrack <2026.2.18634 AngularJS Template Injection XSS
CVE-2026-86484 4.6 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS

XSS

JetBrains YouTrack XSS via Agile Board Custom Field (< 2026.2.18634)
CVE-2026-86483 5.4 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible

XSS

JetBrains YouTrack < 2026.2.18634 PrivEsc via Unchecked Group Membership
CVE-2026-86482 8.8 - High - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation

Incorrect Privilege Assignment

JetBrains YouTrack 2026.2.18634 Signed URL Reuse Disclosure
CVE-2026-86481 4.3 - Medium - September 07, 2026

In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons

Insecure Direct Object Reference / IDOR

JetBrains YouTrack 2026.2.18788 IDOR: Unauthorized REST API Access
CVE-2026-86479 8 - High - September 07, 2026

In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

AuthZ

YouTrack <2025.3.161254 & 2026.1.14042 Unauth Takeover
CVE-2026-86478 9.8 - Critical - September 07, 2026

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

Authentication Bypass by Spoofing

YouTrack 2026.2.17917: Unauthorized Project Transfer Between Orgs
CVE-2026-75051 8.1 - High - August 17, 2026

In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible

AuthZ

YouTrack DoS via crafted type params in <2026.1.13901 & 2026.2.17950
CVE-2026-75050 7.1 - High - August 17, 2026

In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters

Allocation of Resources Without Limits or Throttling

YouTrack Auth Read Rstrctd Articles via Draft-Create EP (v1.13903/v2.17950)
CVE-2026-75049 6.5 - Medium - August 17, 2026

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint

AuthZ

JetBrains YouTrack <2026.2.18068 XSS via Code Label
CVE-2026-75048 8.2 - High - August 17, 2026

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

XSS

JetBrains YouTrack DoS via decompression bomb (pre-2026.2.18177)
CVE-2026-75047 6.5 - Medium - August 17, 2026

In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint

Data Amplification

YouTrack <=2026.2.18112: Auth User Enum via Search (CVE-2026-75046)
CVE-2026-75046 4.3 - Medium - August 17, 2026

In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint

AuthZ

JetBrains YouTrack < 2025.3.156085, 2026.x: Unauth DB backup via draft sig
CVE-2026-75045 9.1 - Critical - August 17, 2026

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

Authentication Bypass Using an Alternate Path or Channel

JetBrains YouTrack 2026.2.18095: Auth Deletion via Mailbox Endpt
CVE-2026-75044 8.1 - High - August 17, 2026

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint

AuthZ

Auth Bypass in JetBrains YouTrack <2026.1.13757 via Direct DB Access
CVE-2026-62422 10 - Critical - July 14, 2026

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

Missing Authentication for Critical Function

JetBrains YouTrack XSS via article title in digest email before 2026.2.17394
CVE-2026-61492 3.5 - Low - July 10, 2026

In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

XSS

YouTrack <2026.2.17012: CSS Injection via Mermaid Diagram
CVE-2026-59791 3.5 - Low - July 10, 2026

In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

Clickjacking

Prototype Pollution in JetBrains YouTrack before 2026.2.16593 Websandbox Bridge
CVE-2026-57926 2.6 - Low - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

Prototype Pollution

YouTrack <=2026.2.16593 Default Role Config Exposes User Profile Details
CVE-2026-57924 4.3 - Medium - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

Incorrect Default Permissions

YouTrack <2026.2.16593 Improper Access Control Read Queries & Tags
CVE-2026-57925 4.3 - Medium - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

AuthZ

YouTrack <2026.2.16593 Improper Auth on App Config Endpoint
CVE-2026-57923 5.3 - Medium - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

AuthZ

JetBrains YouTrack 2026.2.16593 Project Settings Disclosure via MCP
CVE-2026-57922 3.1 - Low - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

AuthZ

YouTrack <2026.2.16593 Improper Access: Read Private Data via Comment Templates
CVE-2026-57921 4.3 - Medium - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

AuthZ

Improper Access Control in JetBrains YouTrack <2026.1.13570 (Planning Canvas)
CVE-2026-49386 6.5 - Medium - May 29, 2026

In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

Insecure Direct Object Reference / IDOR

YouTrack <2026.1.13570 Improper ACL: Low-Privileged Modifies Service Accounts
CVE-2026-49385 6.5 - Medium - May 29, 2026

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

AuthZ

Stored XSS in YouTrack Notification Templates before 2026.1.13162
CVE-2026-49368 8.7 - High - May 29, 2026

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

XSS

YouTrack Info Disclosure before 2026.1.13162 on Users/Groups
CVE-2026-49369 4.3 - Medium - May 29, 2026

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages

AuthZ

YouTrack 2026.1.13162 Info Disclosure via fetchApp
CVE-2026-49370 3.4 - Low - May 29, 2026

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

Insertion of Sensitive Information Into Sent Data

YouTrack 2025.3.131383 RCE via Sandbox Bypass (JetBrains)
CVE-2026-33392 7.2 - High - April 17, 2026

In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

1336

JetBrains YouTrack < 2025.3.121962 AuthBreach via perms endpoint
CVE-2026-28193 8.8 - High - February 25, 2026

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

AuthZ

JetBrains YouTrack <2025.3.119033 access tokens exposed in mailbox logs
CVE-2026-25846 6.5 - Medium - February 09, 2026

In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

Insertion of Sensitive Information into Log File

YouTrack <2025.3.104432 Race Condition Bypass Helpdesk Agent Limit
CVE-2025-64773 2.7 - Low - November 11, 2025

In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit

Race Condition

YouTrack <=2025.3.104432 Junie Token Leak via Misconfig
CVE-2025-64689 - November 10, 2025

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for JetBrains Youtrack or by JetBrains? Click the Watch button to subscribe.

JetBrains
Vendor

subscribe