← Vulnerability feed

Vulnerability record · CVE-2019-12866 · published 3 July 2019

CVE-2019-12866: Jetbrains youtrack insecure direct object reference vulnerability

Jetbrains · Youtrack

An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168.

9.8 CVSS 3.0 Critical EPSS 1.9% · top 20.7% CWE-639 · Insecure direct object reference
9.8CVSS 3.0 base score, v2 7.5
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack. The issue was fixed in 2018.4.49168.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12866 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-62422Jetbrains youtrack missing authentication for critical function vulnerabilityIn JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct…EPSS 0.61%9.8CVE-2026-57926Jetbrains youtrack prototype pollution vulnerabilityIn JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attackEPSS 0.34%9.8CVE-2024-54154Jetbrains youtrack relative path traversal vulnerabilityIn JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandboxEPSS 0.74%9.8CVE-2022-24442Jetbrains youtrack code injection vulnerabilityJetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.EPSS 3.8%9.8CVE-2021-43185Jetbrains youtrack injection vulnerabilityJetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.EPSS 2.0%9.8CVE-2021-25770Jetbrains youtrack code injection vulnerabilityIn JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.EPSS 3.5%9.8CVE-2019-12852Jetbrains youtrack server-side request forgery (ssrf) vulnerabilityAn SSRF attack was possible on a JetBrains YouTrack server. The issue (1 of 2) was fixed in JetBrains YouTrack 2018.4.49168.EPSS 1.8%9.8CVE-2019-12850Jetbrains youtrack sql injection vulnerabilityA query injection was possible in JetBrains YouTrack. The issue was fixed in YouTrack 2018.4.49168.EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2019-12866), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.