CVE-2026-28193

Medium
|5.3
No Exploit

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to send unauthorized requests to the app permissions endpoint in JetBrains YouTrack, potentially gaining access to sensitive information or altering permissions. To exploit this, the attacker needs to be able to interact with the application, meaning they must have some level of access to the YouTrack environment.

Technical Description

In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactNone
Integrity ImpactLow
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References