CVE-2026-57922
YouTrack Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-57922 is an information disclosure vulnerability in JetBrains YouTrack that allows project settings to be exposed via the MCP (Model Context Protocol) interface. It affects all YouTrack versions before 2026.2.16593 and was published on June 26, 2026. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) per NVD, though JetBrains' own scoring via ENISA rates it at 3.1 (Low) with additional authentication requirements factored in (JetBrains Advisory, Feedly).

Détails techniques

The root cause is classified as CWE-862 (Missing Authorization), meaning the MCP interface in YouTrack fails to enforce proper access controls before returning project settings data. An attacker can send network requests to the MCP interface without sufficient privilege checks, causing the application to disclose project configuration information that should be restricted. No user interaction is required, and the attack complexity is low, making it straightforward to trigger once the interface is reachable (Feedly, JetBrains Advisory).

Impact

Successful exploitation results in unauthorized disclosure of project settings, which may include sensitive configuration data such as workflow rules, access policies, custom field definitions, and integration configurations. The impact is limited to confidentiality (no integrity or availability impact), but exposed project settings could assist attackers in planning further targeted attacks against the organization's development infrastructure or identifying misconfigured access controls (Feedly).

Atténuation et solutions de contournement

JetBrains has released a patch in YouTrack version 2026.2.16593, which resolves the missing authorization check in the MCP interface. Organizations should upgrade to version 2026.2.16593 or later as the primary remediation step. As an interim workaround, network access controls should be implemented to restrict MCP interface access to authorized users and systems only, and administrators should audit project settings for any unauthorized disclosures that may have occurred prior to patching (JetBrains Advisory, Feedly).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté YouTrack Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-57926CRITICAL9.8
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026
CVE-2026-57923HIGH7.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026
CVE-2026-57925MEDIUM5.3
  • YouTrack logoYouTrack
  • youtrack
NonOuiJun 26, 2026
CVE-2026-57924MEDIUM5.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026
CVE-2026-57922MEDIUM5.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités