CVE-2026-28193
YouTrack vulnerability analysis and mitigation

Overview

CVE-2026-28193 is a missing authorization vulnerability in JetBrains YouTrack that allows applications to send unauthorized requests to the app permissions endpoint. It affects all YouTrack versions before 2025.3.121962 and was disclosed on February 25, 2026, with a patch released the same day. The CNA (JetBrains) assigned a CVSS v3.1 base score of 8.8 (High), while NVD's independent assessment scored it 5.3 (Medium) — the discrepancy reflects differing assumptions about required privileges (JetBrains Advisory, NVD).

Technical details

The vulnerability is classified as CWE-862 (Missing Authorization), meaning the application fails to perform adequate authorization checks before processing requests to the app permissions endpoint. An attacker (or a malicious app) with low-level network access can craft requests directly to this endpoint, bypassing the intended access control gates that should restrict which principals can query or modify application permissions. No authentication bypass or complex chaining is required beyond having network access to the YouTrack instance, making exploitation straightforward for any app running within the YouTrack ecosystem (NVD, JetBrains Advisory).

Impact

Successful exploitation could allow an attacker or malicious app to read or modify application permission configurations within YouTrack without proper authorization. According to JetBrains' own CVSS assessment (8.8 High), the potential impact spans confidentiality, integrity, and availability — unauthorized access to sensitive project data, unauthorized escalation or modification of app permissions, and potential disruption of YouTrack's permission management system. The scope is limited to the affected YouTrack instance, but compromised permission controls could facilitate further unauthorized actions within the platform (NVD, JetBrains Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is extremely low at 0.003%, reflecting minimal current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible JetBrains YouTrack instances running versions prior to 2025.3.121962 using network scanning tools or service discovery.
  2. Access the permissions endpoint: Send an HTTP request directly to the YouTrack app permissions endpoint without supplying the authorization credentials or tokens that would normally be required.
  3. Enumerate or modify permissions: Leverage the missing authorization check to read current app permission configurations or submit requests that alter permission assignments for installed apps.
  4. Escalate access: Use any newly granted or discovered permissions to access restricted YouTrack projects, issues, or administrative functions beyond the attacker's original privilege level (NVD, JetBrains Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous HTTP requests to the YouTrack app permissions endpoint originating from unfamiliar source IPs or app identities; requests lacking standard authorization headers that would normally accompany legitimate permission queries.
  • Logs: YouTrack application logs showing access to the permissions endpoint from apps or users that should not have that access; repeated or automated requests to the permissions API in short time windows.
  • Application: Unexpected changes to app permission configurations within YouTrack; newly granted permissions for apps that were not explicitly authorized by an administrator.

Mitigation and workarounds

JetBrains has released a fix in YouTrack version 2025.3.121962. All users running versions prior to 2025.3.121962 should upgrade immediately. As a temporary network-level workaround, restrict access to YouTrack instances to trusted networks and limit which apps are permitted to interact with the permissions endpoint until patching is complete (JetBrains Advisory).

Community reactions

Coverage of CVE-2026-28193 has been limited to automated vulnerability tracking platforms and security news aggregators such as The Hacker Wire and INCIBE-CERT, with no notable independent researcher commentary or significant community discussion observed (The Hacker Wire, INCIBE). Social media activity has been minimal, confined to automated CVE broadcast accounts on Bluesky and Mastodon.

Additional resources


SourceThis report was generated using AI

Related YouTrack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57926CRITICAL9.8
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesJun 26, 2026
CVE-2026-61492MEDIUM6.1
  • YouTrack logoYouTrack
  • youtrack
NoYesJul 10, 2026
CVE-2026-57925MEDIUM5.3
  • YouTrack logoYouTrack
  • youtrack
NoYesJun 26, 2026
CVE-2026-57924MEDIUM5.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesJun 26, 2026
CVE-2026-59791LOW3.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesJul 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management