CVE-2026-49386

Published May 29, 2026

Last updated 24 days ago

Overview

Description
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
Source
cve@jetbrains.com
NVD status
Analyzed
Products
youtrack

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

cve@jetbrains.com
CWE-639

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.