Improper Access Control in JetBrains YouTrack Affects Issue Management
CVE-2026-49386
6.5MEDIUM
What is CVE-2026-49386?
JetBrains YouTrack versions prior to 2026.1.13570 have a vulnerability stemming from improper access control, which permits unauthorized users to enumerate restricted issues and articles within the Planning Canvas. This can lead to exposure of sensitive information, allowing malicious actors to gain insights that should be restricted to authorized personnel only. Users are encouraged to update to the latest version to mitigate the risk associated with this access control flaw.
Affected Version(s)
YouTrack 0 < 2026.1.13570