CVE-2026-75049

Summary

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint

Affected Software

VendorProductVersion RangeStatus
JetBrainsYouTrack`0 < 2026.1.13903,
2026.2.17950`affected

Weaknesses

  • CWE-862: CWE-862

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References