CVE-2026-75044: High severity JetBrains YouTrack vulnerability
Published Aug 17, 2026
·Updated
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
Affected Software
1 affected component
JetBrains YouTrack>2025.3.0<=2025.3.156085, >2026.1.0<=2026.1.13914, >2026.2.0<=2026.2.18095
Event History
Aug 17, 2026
CVE Published
via NVD·04:17 PM
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-75044?
CVE-2026-75044 has a severity rating of 8.1, classified as high.
2
How do I fix CVE-2026-75044?
To fix CVE-2026-75044, update JetBrains YouTrack to versions 2025.3.156085, 2026.1.13914, or 2026.2.18095.
3
What impact does CVE-2026-75044 have on JetBrains YouTrack?
CVE-2026-75044 allows authenticated users to delete arbitrary entities via the mailbox endpoint due to missing authorization.
4
Who is affected by CVE-2026-75044?
Authenticated users of JetBrains YouTrack versions prior to the fixed releases are affected by CVE-2026-75044.
5
When was CVE-2026-75044 published?
CVE-2026-75044 was published on August 17, 2026.