PatchSiren cyber security CVE debrief
CVE-2026-75051 JetBrains CVE debrief
CVE-2026-75051 is a high-severity vulnerability in JetBrains YouTrack, allowing unauthorized project transfer between organizations. This vulnerability has significant implications for defenders responsible for YouTrack instances, particularly those with multiple organizations. The vulnerability has a CVSS score of 8.1 and is considered high severity. Defenders should assess exposure and prioritize remediation to prevent potential unauthorized project transfers and lateral movement within instances. The CVE record and NVD entry provide limited information about the vulnerability, with the vendor advisory being the primary source of details. To address this vulnerability, defenders
- Vendor
- JetBrains
- Product
- YouTrack
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-15
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-15
Who should care
Defenders responsible for JetBrains YouTrack instances, especially those with multiple organizations, should assess exposure and prioritize remediation.
Why it matters
CVE-2026-75051 is a high-severity vulnerability in JetBrains YouTrack that allows unauthorized project transfer between organizations. Defenders responsible for YouTrack instances should assess exposure and prioritize remediation to prevent potential unauthorized project transfers and lateral movement within instances.
- Potential unauthorized project transfer between organizations
- Possible lateral movement within YouTrack instances
- Need for verification of exposure and remediation
- Potential impact on project management and security
Technical summary
CVE-2026-75051 is a high-severity vulnerability in JetBrains YouTrack that allows unauthorized project transfer between organizations. The vulnerability has a CVSS score of 8.1 and is considered high severity. This vulnerability affects JetBrains YouTrack instances, particularly those with multiple organizations. Defenders responsible for YouTrack instances should assess exposure and prioritize remediation to prevent potential unauthorized project transfers and lateral movement within instances. The vulnerability can be addressed by verifying exposure and applying
Defensive priority
Defenders should prioritize verifying exposure and remediation for JetBrains YouTrack instances, especially those with unauthorized project transfer between organizations.
Recommended defensive actions
- Verify JetBrains YouTrack instances for exposure to unauthorized project transfer
- Review and apply vendor-provided remediation for CVE-2026-75051
- Monitor for suspicious project transfer activity in YouTrack instances
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, with the vendor advisory being the primary source of details. The vulnerability affects JetBrains YouTrack instances, particularly those with multiple organizations. Defenders should verify exposure and apply remediation to prevent potential unauthorized project transfers. The vendor advisory provides guidance on affected scope, severity, and remediation. However, the advisory may not cover all possible
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75051 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75051
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75051 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75051
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jetbrains.com/privacy-security/issues-fixed/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.