SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75044

HIGH · CVSS 8.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2025.3.156085, 2026.1.13914, and 2026.2.18095 are vulnerable due to a missing authorization flaw that permits authenticated users to delete arbitrary entities through the mailbox endpoint. This vulnerability could lead to unauthorized data loss and potential disruption of services. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-75044
Severity
HIGH
CVSS
8.1
EPSS
0.23%

Original NVD Description

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint

Related CVEs

Other vulnerabilities affecting the same vendor(s)