Missing Authorization in YouTrack - CVE-2026-75051
Published: August 17, 2026
Vulnerability details
The vulnerability allows a remote user to transfer projects between organizations without authorization.
The vulnerability exists due to improper authorization in project transfer functionality when handling project transfer requests. A remote user can initiate an unauthorized project transfer to transfer projects between organizations without authorization.