Authorization Bypass in JetBrains YouTrack Affecting User Data Management
CVE-2026-75044

8.1HIGH

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-75044?

In JetBrains YouTrack versions prior to 2025.3.156085, 2026.1.13914, and 2026.2.18095, a vulnerability exists due to missing authorization checks. This flaw allows authenticated users to delete arbitrary entities through the mailbox endpoint, potentially leading to unauthorized data manipulation and loss. It highlights the need for robust access control measures in software applications to safeguard sensitive data and ensure that only authorized actions are taken.

Affected Version(s)

YouTrack 0 < 2025.3.156085, 2026.1.13914, 2026.2.18095

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.