External risk intelligence

JetBrains YouTrack Unauthenticated Database Backup Download Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-75045

JetBrains YouTrack is typically deployed as a web-based project management and issue-tracking application. Such systems are commonly configured as web services accessible over the network for team collaboration, and in many enterprise environments, they are exposed as web interfaces or portals reachable from the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in JetBrains YouTrack that could allow an unauthorized external attacker to download database backups. This issue could potentially expose sensitive project and user data stored within the YouTrack system.

  • Unauthenticated access to database backups.
  • Protects critical project and user information.
  • Confirm if YouTrack is in use and assess exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by accessing a network-exposed instance of JetBrains YouTrack. The attacker would not need any credentials to initiate the attack. The vulnerability lies in the handling of shared draft signatures, which, when triggered, allows the attacker to download database backups. This could lead to the exposure of sensitive information contained within the backups.

  • No authentication required.
  • Download database backups via shared draft.
  • Risk of sensitive data exposure.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could download database backups when supported by the advisory. This could expose sensitive system and user data.

  • Database backups could be at risk.
  • Backups may be downloaded via shared draft signature.
  • Sensitive data exposure is a potential consequence.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for application security and the deployed environment, such as infrastructure or platform teams, should lead the response to this vulnerability. The initial step is to confirm where JetBrains YouTrack is deployed, assess its reachability and criticality, and then identify the accountable owner to plan remediation.

  • Application owners should manage the issue.
  • Verify external reachability and business criticality first.
  • Coordinate vendor updates and plan maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is JetBrains YouTrack?

JetBrains YouTrack is a project management and issue-tracking platform used by teams to organize tasks, track bugs, and manage software development workflows. It serves as a centralized hub for project documentation and communication, often holding significant amounts of sensitive organizational and user data.

What does CWE-288 mean for CVE-2026-75045?

CWE-288 refers to authentication bypass using an alternate path or channel. In the context of this vulnerability, it means the software's security controls can be circumvented, allowing an attacker to access sensitive database backups without providing valid login credentials, effectively ignoring the system's normal authentication requirements.

How can an attacker trigger this vulnerability?

An attacker triggers this issue by interacting with shared draft signatures within the application. Crucially, this does not require a compromised account or any prior authorization. Simply navigating to or manipulating these specific signature paths is sufficient to facilitate the unauthorized download of database backups.

Do I need to worry if my YouTrack instance is internal?

Halo Surface Signal indicates that while YouTrack is frequently exposed to the internet to support remote team collaboration, the risk level depends on your specific deployment. If your instance is not reachable from the public internet, the attack surface is significantly reduced, though you should still verify your internal access controls and update status.

What should I do first to address CVE-2026-75045?

Your first step is to locate all instances of YouTrack within your environment to determine which versions are running. Once you have identified these installations, check them against the affected version list in the advisory. Coordinate with the system owners to prioritize these assets and prepare for the necessary vendor updates to secure your database backups.

References