Sceawere

Vulnerability Detail

CVE-2026-75049UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JetBrains YouTrack Restricted Article Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
5h ago
Vendor
JetBrains
Product
YouTrack
Attack Type
CWE-862
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-17T16:17:51.987Z",
  "pubdate": "2026-08-17T16:17:51.987Z",
  "executiveSummary": "A vulnerability exists in JetBrains YouTrack prior to versions 2026.1.13903 and 2026.2.17950, allowing an authenticated user to gain unauthorized read access to restricted articles belonging to other projects. This security flaw stems from insufficient authorization checks within the draft creation endpoint, failing to properly validate whether the requesting user possesses adequate permissions to access the target project's restricted content. The risk implication is significant as it breaches confidentiality boundaries within multi-project environments, enabling lower-privileged or cross-project users to harvest sensitive organizational data stored in article drafts. Exploitation of this vulnerability requires an authenticated session on the target YouTrack instance, granting the attacker the capability to interact with the draft creation mechanism and extract unauthorized information. No complex preconditions or administrative privileges are necessary beyond standard user authentication, lowering the barrier for potential exploitation by malicious insiders or compromised accounts.",
  "technicalDetails": "The vulnerability resides within the article draft creation endpoint of JetBrains YouTrack, specifically affecting versions prior to 2026.1.13903 and 2026.2.17950. The root cause of the issue is an improper authorization enforcement flaw in the backend logic handling draft initialization and persistence. When a client initiates a request to the draft creation component, the application fails to adequately verify if the authenticated user has explicit read permissions for the specific project associated with the target resource. Consequently, the access control check evaluates user privileges too leniently or omits project-level scoping entirely during the draft instantiation phase.\nTo exploit this vulnerability, an attacker must possess a valid, authenticated user account within the target JetBrains YouTrack instance. The attack flow begins by crafting an HTTP request directed at the vulnerable draft creation endpoint. By manipulating request parameters to reference restricted articles or cross-project identifiers, the attacker bypasses standard access restrictions. Because the backend component processes the input without verifying cross-project access constraints, it instantiates or interacts with the draft and inadvertently leaks the restricted article content in the server response or permits unauthorized state manipulation. The vulnerable component processes input handling for drafts without enforcing principle-of-least-privilege access controls.\nThe network exposure is bounded by the accessibility of the YouTrack web application interface, requiring network connectivity to the instance. The post-exploitation impact is characterized by a breach of data confidentiality, allowing unauthorized retrieval of proprietary documentation, internal knowledge base drafts, and sensitive operational notes restricted to specific project teams or administrators."
}
CVE-2026-75049: JetBrains YouTrack Restricted Article Information Disclosure (MEDIUM Severity, CVSS: 6.5) - Sceawere