PatchSiren cyber security CVE debrief
CVE-2026-75045 JetBrains CVE debrief
CVE-2026-75045 debrief based on the supplied source corpus. The vulnerability affects JetBrains YouTrack instances before 2025.3.156085, 2026.1.13913, and 2026.2.18112, allowing unauthenticated attackers to download database backups via shared draft signatures. Defenders should assess exposure, prioritize remediation, and verify instance security to prevent potential data breaches and service disruptions. This vulnerability has a critical CVSS score of 9.1, emphasizing the need for immediate attention. The CVE record and NVD entry provide details, but vendor advisory information is limited. Affected product deployments should be identified, and owners assigned for follow-up. The de
- Vendor
- JetBrains
- Product
- YouTrack
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-15
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-15
Who should care
Defenders responsible for JetBrains YouTrack instances, especially those with shared draft signatures enabled, should assess exposure and prioritize remediation.
Why it matters
CVE-2026-75045 is a critical vulnerability in JetBrains YouTrack that allows unauthenticated attackers to download database backups. Defenders responsible for YouTrack instances should assess exposure, prioritize remediation, and verify instance security to prevent potential data breaches and service disruptions.
- Potential unauthorized access to sensitive data in database backups.
- Possible disruption of service due to exposure of critical system information.
- Need for verification of instance exposure and remediation status.
- Potential for lateral movement or further exploitation if not properly addressed.
Technical summary
CVE-2026-75045 is a critical vulnerability in JetBrains YouTrack, allowing unauthenticated attackers to download database backups via shared draft signatures. Affected versions include those before 2025.3.156085, 2026.1.13913, and 2026.2.18112. The vulnerability has a CVSS score of 9.1, indicating critical severity. Defenders should prioritize verifying exposure and remediation for JetBrains YouTrack instances, especially those with shared draft signatures enabled. The vulnerability allows for potential unauthorized access to sensitive data in database backups and
Defensive priority
Defenders should prioritize verifying exposure and remediation for JetBrains YouTrack instances, especially those with shared draft signatures enabled.
Recommended defensive actions
- Verify JetBrains YouTrack instance exposure, especially for shared draft signatures.
- Check for and apply vendor-provided patches or updates.
- Monitor for potential unauthorized access to database backups.
- Restrict access to sensitive areas of the YouTrack instance.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but vendor advisory information is limited. Evidence is based on CVE and NVD data, with limited vendor input. Defenders should verify instance exposure, check for patches, and monitor for unauthorized access. The vulnerability allows unauthenticated attackers to download database backups via shared draft signatures in JetBrains YouTrack before 2025.3.156085, 2026.1.13913, and 2026.2.18112. Affected scope and severity
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75045 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75045
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75045 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75045
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jetbrains.com/privacy-security/issues-fixed/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.