CVE-2026-75044 – JetBrains YouTrack

CVSS 8.1 IMPORTANT Critical - Same Day Deployment

“Weak authorization controls can expose backups, delete data, and move projects across organizational boundaries.”

JetBrains fixes three serious YouTrack vulnerabilities. CVE-2026-75045 allows an unauthenticated attacker to download database backups through a shared draft signature. The CVSS score is 9.1, which is Critical severity. CVE-2026-75044 allows an authenticated user to delete arbitrary entities through the mailbox endpoint. CVE-2026-75044 has a CVSS score of 8.1, High severity.

CVE-2026-75051 allows an authenticated user to transfer projects between organizations without proper authorization. CVE-2026-75051 has a CVSS score of 8.1, High severity. Fixed builds vary by supported YouTrack release branch.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-862
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.