2026.1.13914,
2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ |
|
Mon, 17 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated User Can Delete Arbitrary Entities via Mailbox Endpoint in JetBrains YouTrack | |
| First Time appeared |
Jetbrains
Jetbrains youtrack |
|
| Vendors & Products |
Jetbrains
Jetbrains youtrack |
Mon, 17 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: JetBrains
Published:
Updated: 2026-08-17T16:17:18.306Z
Reserved: 2026-08-17T15:34:06.256Z
Link: CVE-2026-75044
Updated: 2026-08-17T16:17:12.241Z
Status : Received
Published: 2026-08-17T16:17:51.410
Modified: 2026-08-17T17:16:53.327
Link: CVE-2026-75044
No data.
OpenCVE Enrichment
Updated: 2026-08-17T18:00:05Z