Authorization Bypass in JetBrains YouTrack Affecting User Data Management
CVE-2026-75044
8.1HIGH
What is CVE-2026-75044?
In JetBrains YouTrack versions prior to 2025.3.156085, 2026.1.13914, and 2026.2.18095, a vulnerability exists due to missing authorization checks. This flaw allows authenticated users to delete arbitrary entities through the mailbox endpoint, potentially leading to unauthorized data manipulation and loss. It highlights the need for robust access control measures in software applications to safeguard sensitive data and ensure that only authorized actions are taken.
Affected Version(s)
YouTrack 0 < 2025.3.156085, 2026.1.13914, 2026.2.18095