Youtrack JetBrains Youtrack

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in JetBrains Youtrack.

By the Year

In 2026 there have been 17 vulnerabilities in JetBrains Youtrack with an average score of 5.5 out of ten. Last year, in 2025 Youtrack had 15 security vulnerabilities published. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.26




Year Vulnerabilities Average Score
2026 17 5.46
2025 15 5.72
2024 28 6.09
2023 4 6.13
2022 7 5.87
2021 21 6.56
2020 18 6.04
2019 11 6.10

It may take a day or so for new Youtrack vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent JetBrains Youtrack Security Vulnerabilities

Auth Bypass in JetBrains YouTrack <2026.1.13757 via Direct DB Access
CVE-2026-62422 10 - Critical - July 14, 2026

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

Missing Authentication for Critical Function

JetBrains YouTrack XSS via article title in digest email before 2026.2.17394
CVE-2026-61492 3.5 - Low - July 10, 2026

In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible

XSS

YouTrack <2026.2.17012: CSS Injection via Mermaid Diagram
CVE-2026-59791 3.5 - Low - July 10, 2026

In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible

Clickjacking

Prototype Pollution in JetBrains YouTrack before 2026.2.16593 Websandbox Bridge
CVE-2026-57926 2.6 - Low - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

Prototype Pollution

YouTrack <2026.2.16593 Improper Access Control Read Queries & Tags
CVE-2026-57925 4.3 - Medium - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

AuthZ

YouTrack <=2026.2.16593 Default Role Config Exposes User Profile Details
CVE-2026-57924 4.3 - Medium - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

Incorrect Default Permissions

YouTrack <2026.2.16593 Improper Auth on App Config Endpoint
CVE-2026-57923 5.3 - Medium - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

AuthZ

JetBrains YouTrack 2026.2.16593 Project Settings Disclosure via MCP
CVE-2026-57922 3.1 - Low - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

AuthZ

YouTrack <2026.2.16593 Improper Access: Read Private Data via Comment Templates
CVE-2026-57921 4.3 - Medium - June 26, 2026

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

AuthZ

Improper Access Control in JetBrains YouTrack <2026.1.13570 (Planning Canvas)
CVE-2026-49386 6.5 - Medium - May 29, 2026

In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

Insecure Direct Object Reference / IDOR

YouTrack <2026.1.13570 Improper ACL: Low-Privileged Modifies Service Accounts
CVE-2026-49385 6.5 - Medium - May 29, 2026

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

AuthZ

YouTrack 2026.1.13162 Info Disclosure via fetchApp
CVE-2026-49370 3.4 - Low - May 29, 2026

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

Insertion of Sensitive Information Into Sent Data

YouTrack Info Disclosure before 2026.1.13162 on Users/Groups
CVE-2026-49369 4.3 - Medium - May 29, 2026

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages

AuthZ

Stored XSS in YouTrack Notification Templates before 2026.1.13162
CVE-2026-49368 8.7 - High - May 29, 2026

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

XSS

YouTrack 2025.3.131383 RCE via Sandbox Bypass (JetBrains)
CVE-2026-33392 7.2 - High - April 17, 2026

In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass

1336

JetBrains YouTrack < 2025.3.121962 AuthBreach via perms endpoint
CVE-2026-28193 8.8 - High - February 25, 2026

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

AuthZ

JetBrains YouTrack <2025.3.119033 access tokens exposed in mailbox logs
CVE-2026-25846 6.5 - Medium - February 09, 2026

In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

Insertion of Sensitive Information into Log File

YouTrack <2025.3.104432 Race Condition Bypass Helpdesk Agent Limit
CVE-2025-64773 2.7 - Low - November 11, 2025

In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit

Race Condition

YouTrack <=2025.3.104432 Junie Token Leak via Misconfig
CVE-2025-64689 - November 10, 2025

YouTrack TLS Cert Validation Bypass CVE-2025-64685 (pre 2025.3.104432)
CVE-2025-64685 8.1 - High - November 10, 2025

In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure

Improper Certificate Validation

CVE-2025-64684: YouTrack < 2025.3.104432 Info Disclosure via Feedback Form
CVE-2025-64684 4.5 - Medium - November 10, 2025

In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form

AuthZ

YouTrack XSS via Mermaid diagram pre-2025.2.92387
CVE-2025-57731 - August 20, 2025

In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content

XSS

YouTrack XSS via iframe sandbox bypass before 2025.2.86935
CVE-2025-54527 - July 28, 2025

In JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allows popups to bypass security restrictions

Clickjacking

YouTrack < 2025.2.86069 Email Spoofing via Admin API
CVE-2025-53959 - July 15, 2025

In JetBrains YouTrack before 2025.2.86069, 2024.3.85077, 2025.1.86199 email spoofing via an administrative API was possible

AuthZ

YouTrack <2025.1.74704> restricted attachments visible after cloning
CVE-2025-47850 - May 20, 2025

In JetBrains YouTrack before 2025.1.74704 restricted attachments could become visible after issue cloning

Missing Authentication for Critical Function

JetBrains YouTrack <=2025.1.76253 API: Issue Deletion w/o Permission Check
CVE-2025-48391 - May 20, 2025

In JetBrains YouTrack before 2025.1.76253 deletion of issues was possible due to missing permission checks in API

Missing Authentication for Critical Function

YouTrack Before 2024.3 Permanent Tokens Logged in Logs
CVE-2025-24457 5.5 - Medium - January 21, 2025

In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs

Insertion of Sensitive Information into Log File

Account Takeover: JetBrains YouTrack <2024.3.55417 via Email Spoof
CVE-2025-24458 7.8 - High - January 21, 2025

In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration

Authentication Bypass by Spoofing

JetBrains YouTrack Unauthenticated Database Backup Download Vulnerability
CVE-2024-54153 6.5 - Medium - December 04, 2024

In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

Missing Authentication for Critical Function

JetBrains YouTrack Path Traversal Vulnerability in Plugin Sandbox
CVE-2024-54154 9.8 - Critical - December 04, 2024

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

Directory traversal

JetBrains YouTrack Improper Access Control Vulnerability in Project Listing
CVE-2024-54155 5.3 - Medium - December 04, 2024

In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

Missing Authentication for Critical Function

JetBrains YouTrack Multiple Merge Functions Prototype Pollution Vulnerability
CVE-2024-54156 6.5 - Medium - December 04, 2024

In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack

Prototype Pollution

JetBrains YouTrack Ruby Syntax Detector ReDoS Vulnerability
CVE-2024-54157 6.5 - Medium - December 04, 2024

In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector

ReDoS

JetBrains YouTrack Punycode Encoding Spoofing Vulnerability
CVE-2024-54158 5.3 - Medium - December 04, 2024

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

Authentication Bypass by Spoofing

ReDoS in JetBrains YouTrack 2024.3 Helpdesk email header parse pre-2024.3.47707
CVE-2024-50574 7.5 - High - October 28, 2024

In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality

ReDoS

YouTrack <2024.3.47707> XSS via Improper HTML Sanitization in Markdown
CVE-2024-50582 5.4 - Medium - October 28, 2024

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements

XSS

JetBrains YouTrack <2024.3.47707: XSS via comment tag
CVE-2024-50581 5.4 - Medium - October 28, 2024

In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag

XSS

YouTrack XSS via insecure markdown parsing before 2024.3.47707
CVE-2024-50580 5.4 - Medium - October 28, 2024

In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule

XSS

JetBrains YouTrack 2024.3.47707 Reflected XSS via Insecure Link Sanitization
CVE-2024-50579 6.1 - Medium - October 28, 2024

In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible

XSS

JetBrains YouTrack 2024.3.47707- Store XSS via Sprint Value on Agile Boards
CVE-2024-50578 5.4 - Medium - October 28, 2024

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page

XSS

XSS via Angular Template Injection in JetBrains YouTrack <2024.3.47707 Hub Settings
CVE-2024-50577 5.4 - Medium - October 28, 2024

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings

XSS

JetBrains YouTrack 2024.3.47707 Stored XSS via Vendor URL
CVE-2024-50576 5.4 - Medium - October 28, 2024

In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest

XSS

Reflected XSS in JetBrains YouTrack Widget API before 2024.3.47707
CVE-2024-50575 6.1 - Medium - October 28, 2024

In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API

XSS

JetBrains YouTrack <2024.3.47197: insecure iframe -> exec arbitrary JS
CVE-2024-49579 6.1 - Medium - October 17, 2024

In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests

Improper Verification of Source of a Communication Channel

JetBrains YouTrack <2024.3.46677 Imp. Acc. Control API Delete
CVE-2024-48902 5.4 - Medium - October 10, 2024

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API

AuthZ

JetBrains YouTrack <2024.3.44799 Unauth Access to Global Config
CVE-2024-47160 5.3 - Medium - September 19, 2024

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

AuthZ

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for JetBrains Youtrack or by JetBrains? Click the Watch button to subscribe.

JetBrains
Vendor

subscribe