JetBrains YouTrack Improper Access Control Vulnerability Allowing Enumeration of Restricted Issues

Vulnerability

A vulnerability in JetBrains YouTrack versions prior to 2026.1.13570 allows low-privileged users to improperly access and enumerate restricted issues and articles on the Planning Canvas. This issue arises from inadequate access control measures, which fail to prevent unauthorized users from viewing sensitive information.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of restricted issues and articles, allowing users to access information they should not be privy to.

Remediation

Users can upgrade to JetBrains YouTrack version 2026.1.13570 or later to address this vulnerability.

Added: May 29, 2026, 7:19 PM
Updated: May 29, 2026, 7:19 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.