CVE-2026-57921

EUVD-2026-39653
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.38%
Affected Products (NVD)
VendorProductVersion
jetbrainsyoutrack
𝑥
< 2026.2.16593
𝑥
= Vulnerable software versions