Access Control Vulnerability in JetBrains YouTrack Software
CVE-2026-75049
6.5MEDIUM
What is CVE-2026-75049?
In JetBrains YouTrack versions prior to 2026.1.13903 and 2026.2.17950, an authenticated user could exploit the draft creation endpoint to access restricted articles from other projects, posing a significant risk to data confidentiality. This vulnerability underscores the importance of robust access control measures to prevent unauthorized information access within project management tools.
Affected Version(s)
YouTrack 0 < 2026.1.13903, 2026.2.17950