Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3155 articles · 168089 vulns · 37/41 feeds (7d)
← Back to list
4.3
CVE-2026-57925PATCHED
jetbrains · youtrack

CVE-2026-57925: In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

Description

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

Affected Products

VendorProductVersions
jetbrainsyoutrack0, 2026.1.13570

References

  • https://www.jetbrains.com/privacy-security/issues-fixed/

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-57925 | JetBrains YouTrack up to 2026.1.13570 authorization
→ No new info (linked only)
CVSS 3.14.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.2.16593
CWECWE-862
PublishedJun 26, 2026
Last enriched1d agov2
Tags
authorization
Trending Score20
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-57924EXP
CVE-2026-57924: In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
Trending: 41
MEDIUMCVE-2026-57926EXP
CVE-2026-57926: In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
Trending: 35
MEDIUMCVE-2026-57922EXP
CVE-2026-57922: In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible
Trending: 35
MEDIUMCVE-2026-53914
CVE-2026-53914: In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
Trending: 24
HIGHCVE-2026-57921
CVE-2026-57921: In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment te
Trending: 23

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 26, 2026
Discovered by ZDM
Jun 26, 2026
Patch Available
Jun 26, 2026
Updated: affectedVersions, tags
Jun 26, 2026

Version History

v2
Last enriched 1d ago
v2Tier C1d ago

Updated affected versions to include 2026.1.13570 and added new tag 'authorization'.

affectedVersionstags
via VulDB
v11d ago

Initial creation