Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3191 articles · 168085 vulns · 37/41 feeds (7d)
← Back to list
4.3
CVE-2026-57924EXPLOITEDPATCHED
jetbrains · youtrack

CVE-2026-57924: In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

Description

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

Affected Products

VendorProductVersions
jetbrainsyoutrack0

References

  • https://www.jetbrains.com/privacy-security/issues-fixed/

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-57924 | JetBrains YouTrack up to 2026.1.13570 Configuration default permission
→ No new info (linked only)
CVSS 3.14.3 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2026.2.16593
CWECWE-276
PublishedJun 26, 2026
Last enriched1d agov2
Tags
configurationpermissions
Trending Score41
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-57926EXP
CVE-2026-57926: In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
Trending: 35
MEDIUMCVE-2026-57922EXP
CVE-2026-57922: In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
Trending: 35
MEDIUMCVE-2026-53914
CVE-2026-53914: In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
Trending: 24
HIGHCVE-2026-57921
CVE-2026-57921: In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment te
Trending: 23
MEDIUMCVE-2026-57925
CVE-2026-57925: In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
Trending: 20

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 26, 2026
Discovered by ZDM
Jun 26, 2026
Actively Exploited
Jun 26, 2026
Patch Available
Jun 26, 2026
Updated: severity, activelyExploited, tags
Jun 26, 2026

Version History

v2
Last enriched 1d ago
v2Tier C1d ago

Updated severity to CRITICAL, marked as actively exploited, and added new tags related to configuration and permissions.

severityactivelyExploitedtags
via VulDB
v11d ago

Initial creation