PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75045 JetBrains CVE debrief

CVE-2026-75045 debrief based on the supplied source corpus. The vulnerability affects JetBrains YouTrack instances before 2025.3.156085, 2026.1.13913, and 2026.2.18112, allowing unauthenticated attackers to download database backups via shared draft signatures. Defenders should assess exposure, prioritize remediation, and verify instance security to prevent potential data breaches and service disruptions. This vulnerability has a critical CVSS score of 9.1, emphasizing the need for immediate attention. The CVE record and NVD entry provide details, but vendor advisory information is limited. Affected product deployments should be identified, and owners assigned for follow-up. The de

Vendor
JetBrains
Product
YouTrack
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-15
Advisory published
2026-08-17
Advisory updated
2026-09-15

Who should care

Defenders responsible for JetBrains YouTrack instances, especially those with shared draft signatures enabled, should assess exposure and prioritize remediation.

Why it matters

CVE-2026-75045 is a critical vulnerability in JetBrains YouTrack that allows unauthenticated attackers to download database backups. Defenders responsible for YouTrack instances should assess exposure, prioritize remediation, and verify instance security to prevent potential data breaches and service disruptions.

  • Potential unauthorized access to sensitive data in database backups.
  • Possible disruption of service due to exposure of critical system information.
  • Need for verification of instance exposure and remediation status.
  • Potential for lateral movement or further exploitation if not properly addressed.

Technical summary

CVE-2026-75045 is a critical vulnerability in JetBrains YouTrack, allowing unauthenticated attackers to download database backups via shared draft signatures. Affected versions include those before 2025.3.156085, 2026.1.13913, and 2026.2.18112. The vulnerability has a CVSS score of 9.1, indicating critical severity. Defenders should prioritize verifying exposure and remediation for JetBrains YouTrack instances, especially those with shared draft signatures enabled. The vulnerability allows for potential unauthorized access to sensitive data in database backups and

Defensive priority

Defenders should prioritize verifying exposure and remediation for JetBrains YouTrack instances, especially those with shared draft signatures enabled.

Recommended defensive actions

  • Verify JetBrains YouTrack instance exposure, especially for shared draft signatures.
  • Check for and apply vendor-provided patches or updates.
  • Monitor for potential unauthorized access to database backups.
  • Restrict access to sensitive areas of the YouTrack instance.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but vendor advisory information is limited. Evidence is based on CVE and NVD data, with limited vendor input. Defenders should verify instance exposure, check for patches, and monitor for unauthorized access. The vulnerability allows unauthenticated attackers to download database backups via shared draft signatures in JetBrains YouTrack before 2025.3.156085, 2026.1.13913, and 2026.2.18112. Affected scope and severity

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75045 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75045

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75045 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75045

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.