CyberRota Analysis
AI-GeneratedJetBrains YouTrack versions prior to 2025.3.156085, 2026.1.13914, and 2026.2.18095 are vulnerable due to a missing authorization flaw that permits authenticated users to delete arbitrary entities through the mailbox endpoint. This vulnerability could lead to unauthorized data loss and potential disruption of services. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.
CVE
CVE-2026-75044
Severity
HIGH
CVSS
8.1
EPSS
0.23%
Original NVD Description
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
Related CVEs
Other vulnerabilities affecting the same vendor(s)