CVE-2026-75045: JetBrains Youtrack

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

Affected products

  • JetBrains Youtrack: before 2025.3.156085 (fixed in 2025.3.156085); from 2026.1, before 2026.1.13913 (fixed in 2026.1.13913); from 2026.2, before 2026.2.18112 (fixed in 2026.2.18112)

Published 2026-08-17. Last modified 2026-09-15.