
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75046 is an account enumeration vulnerability in JetBrains YouTrack that allows authenticated users to discover valid user accounts via the users search endpoint. It affects all YouTrack versions before 2026.2.18112 and was disclosed on August 17, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), assigned by JetBrains (GitHub Advisory, JetBrains).
The root cause is a missing authorization check (CWE-862) on the users search endpoint in JetBrains YouTrack. An authenticated user with low privileges can query this endpoint to enumerate valid accounts, receiving responses that reveal the existence and details of user accounts in the system. Exploitation requires only a valid authenticated session and network access to the YouTrack instance — no elevated privileges or user interaction are needed (GitHub Advisory, JetBrains).
Successful exploitation allows a low-privileged authenticated attacker to enumerate valid user accounts within the YouTrack instance, disclosing account existence and associated details. This is a confidentiality-only impact with no effect on integrity or availability. The exposed account information could facilitate targeted phishing, credential stuffing, or further privilege escalation attempts against identified accounts (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation is not automatable per NVD SSVC assessment, as it requires an authenticated session (GitHub Advisory).
/api/users or similar YouTrack REST API path)./api/users) from a single authenticated session, particularly with iterative or pattern-based query parameters.Upgrade JetBrains YouTrack to version 2026.2.18112 or later, which contains the fix for this vulnerability. As a temporary workaround prior to patching, consider restricting access to the users search endpoint for low-privileged authenticated users through network-level controls or application firewall rules. Monitor the users search endpoint for anomalous query patterns as a compensating control (JetBrains, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."