CVE-2026-75044

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*:*
cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-17 16:17

Updated : 2026-09-15 17:46


NVD link : CVE-2026-75044

Mitre link : CVE-2026-75044

CVE.ORG link : CVE-2026-75044


JSON object : View

Products Affected

jetbrains

  • youtrack
CWE
CWE-862

Missing Authorization