
PEACH
Un cadre d’isolation des locataires
CVE-2026-57925 is an improper access control vulnerability in JetBrains YouTrack that allows unauthorized reading of saved queries and tags. It affects all versions of YouTrack before 2026.2.16593 and was disclosed on June 26, 2026. The vulnerability has a CVSS v3.1 base score of 5.3 (Medium) per NVD, or 4.3 (Medium) per ENISA/EUVD (JetBrains Advisory).
The root cause is classified as CWE-862 (Missing Authorization), where the application fails to enforce proper access control checks before returning saved queries and tags to requesting users. An unauthenticated or low-privileged network attacker can send crafted requests to the YouTrack API to retrieve saved queries and tags that should be restricted to authorized users. No special preconditions such as user interaction or elevated privileges are required for exploitation, making the attack straightforward for any network-accessible instance (JetBrains Advisory).
Successful exploitation allows an attacker to read saved search queries and tags that should be access-controlled, potentially exposing sensitive search criteria, project organization details, and internal workflow structures. The impact is limited to confidentiality — there is no integrity or availability impact — but the exposed data could reveal information about project structure, issue categorization, and team workflows that could aid further reconnaissance or targeted attacks (JetBrains Advisory).
JetBrains has released a fix in YouTrack version 2026.2.16593. Organizations should upgrade to this version or later as the primary remediation. As an interim measure until patching is possible, administrators should restrict YouTrack access to trusted and authenticated users only, and review existing access control configurations to limit exposure of saved queries and tags (JetBrains Advisory).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."