CVE-2026-57925
YouTrack Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-57925 is an improper access control vulnerability in JetBrains YouTrack that allows unauthorized reading of saved queries and tags. It affects all versions of YouTrack before 2026.2.16593 and was disclosed on June 26, 2026. The vulnerability has a CVSS v3.1 base score of 5.3 (Medium) per NVD, or 4.3 (Medium) per ENISA/EUVD (JetBrains Advisory).

Détails techniques

The root cause is classified as CWE-862 (Missing Authorization), where the application fails to enforce proper access control checks before returning saved queries and tags to requesting users. An unauthenticated or low-privileged network attacker can send crafted requests to the YouTrack API to retrieve saved queries and tags that should be restricted to authorized users. No special preconditions such as user interaction or elevated privileges are required for exploitation, making the attack straightforward for any network-accessible instance (JetBrains Advisory).

Impact

Successful exploitation allows an attacker to read saved search queries and tags that should be access-controlled, potentially exposing sensitive search criteria, project organization details, and internal workflow structures. The impact is limited to confidentiality — there is no integrity or availability impact — but the exposed data could reveal information about project structure, issue categorization, and team workflows that could aid further reconnaissance or targeted attacks (JetBrains Advisory).

Atténuation et solutions de contournement

JetBrains has released a fix in YouTrack version 2026.2.16593. Organizations should upgrade to this version or later as the primary remediation. As an interim measure until patching is possible, administrators should restrict YouTrack access to trusted and authenticated users only, and review existing access control configurations to limit exposure of saved queries and tags (JetBrains Advisory).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté YouTrack Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-57926CRITICAL9.8
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026
CVE-2026-57923HIGH7.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026
CVE-2026-57925MEDIUM5.3
  • YouTrack logoYouTrack
  • youtrack
NonOuiJun 26, 2026
CVE-2026-57924MEDIUM5.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026
CVE-2026-57922MEDIUM5.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NonOuiJun 26, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités