Authorization bypass through user-controlled key in YouTrack - CVE-2026-49386
Published: August 17, 2026
Vulnerability details
The vulnerability allows a remote user to disclose restricted issue and article information.
The vulnerability exists due to improper access control in Planning Canvas when handling requests for restricted issues and articles. A remote user can access Planning Canvas to enumerate restricted issues and articles to disclose restricted issue and article information.