Incomplete in the CWE catalog · 2,302 CVEs mapped
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint