
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28193 is a missing authorization vulnerability in JetBrains YouTrack that allows applications to send unauthorized requests to the app permissions endpoint. It affects all YouTrack versions before 2025.3.121962 and was disclosed on February 25, 2026, with a patch released the same day. The CNA (JetBrains) assigned a CVSS v3.1 base score of 8.8 (High), while NVD's independent assessment scored it 5.3 (Medium) — the discrepancy reflects differing assumptions about required privileges (JetBrains Advisory, NVD).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the application fails to perform adequate authorization checks before processing requests to the app permissions endpoint. An attacker (or a malicious app) with low-level network access can craft requests directly to this endpoint, bypassing the intended access control gates that should restrict which principals can query or modify application permissions. No authentication bypass or complex chaining is required beyond having network access to the YouTrack instance, making exploitation straightforward for any app running within the YouTrack ecosystem (NVD, JetBrains Advisory).
Successful exploitation could allow an attacker or malicious app to read or modify application permission configurations within YouTrack without proper authorization. According to JetBrains' own CVSS assessment (8.8 High), the potential impact spans confidentiality, integrity, and availability — unauthorized access to sensitive project data, unauthorized escalation or modification of app permissions, and potential disruption of YouTrack's permission management system. The scope is limited to the affected YouTrack instance, but compromised permission controls could facilitate further unauthorized actions within the platform (NVD, JetBrains Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is extremely low at 0.003%, reflecting minimal current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
JetBrains has released a fix in YouTrack version 2025.3.121962. All users running versions prior to 2025.3.121962 should upgrade immediately. As a temporary network-level workaround, restrict access to YouTrack instances to trusted networks and limit which apps are permitted to interact with the permissions endpoint until patching is complete (JetBrains Advisory).
Coverage of CVE-2026-28193 has been limited to automated vulnerability tracking platforms and security news aggregators such as The Hacker Wire and INCIBE-CERT, with no notable independent researcher commentary or significant community discussion observed (The Hacker Wire, INCIBE). Social media activity has been minimal, confined to automated CVE broadcast accounts on Bluesky and Mastodon.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."