CVE-2026-57924
YouTrack Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-57924 is an information disclosure vulnerability in JetBrains YouTrack caused by incorrect default role configuration that exposes excessive user profile details to authenticated users. It affects all versions of JetBrains YouTrack before 2026.2.16593. The vulnerability was published on June 26, 2026, and a patch was made available the same day (JetBrains). It carries a CVSS v3.1 base score of 5.3 (Medium) per NVD, and 4.3 (Medium) per JetBrains/ENISA, reflecting a low-severity confidentiality impact with no integrity or availability impact.

Détails techniques

The root cause is classified as CWE-276 (Incorrect Default Permissions), where the default role configuration in YouTrack grants authenticated users access to user profile details beyond what is appropriate. An attacker with a valid account can query the application over the network without elevated privileges to retrieve sensitive profile information that should be restricted by role-based access controls. No special conditions, user interaction, or complex attack chain is required beyond authentication (JetBrains). No public technical write-ups or proof-of-concept code have been identified at this time.

Impact

Successful exploitation results in unauthorized disclosure of user profile details within the YouTrack instance, representing a confidentiality impact. There is no impact to integrity or availability. The exposed information could include personal or organizational data about users (e.g., email addresses, names, or other profile fields), which could facilitate targeted phishing, social engineering, or account enumeration against the organization's development or project management team (JetBrains).

Atténuation et solutions de contournement

JetBrains has released a fix in YouTrack version 2026.2.16593. Organizations should upgrade to this version or later as the primary remediation step (JetBrains). As a supplementary measure, administrators should review and audit default role configurations within YouTrack to ensure user profile fields are restricted according to the principle of least privilege. Limiting network access to YouTrack instances to trusted users can also reduce exposure.

Réactions de la communauté

Coverage of this vulnerability has been limited to automated vulnerability tracking platforms and feeds, including Tenable, VulnDB, and ENISA's EUVD. No notable researcher commentary or significant community discussion has been identified beyond standard CVE publication and aggregation.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté YouTrack Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-57926CRITICAL9.8
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026
CVE-2026-57923HIGH7.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026
CVE-2026-57925MEDIUM5.3
  • YouTrack logoYouTrack
  • youtrack
NonOuiJun 26, 2026
CVE-2026-57924MEDIUM5.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026
CVE-2026-57922MEDIUM5.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités