JetBrains YouTrack: 22 Vulnerabilities Disclosed, Ranging from Account Takeover to Privilege Escalation
JetBrains YouTrack: 22 vulnerabilities disclosed, including critical flaws enabling account takeover and privilege escalation.

Key findings
- 22 vulnerabilities disclosed simultaneously for JetBrains YouTrack on September 7, 2026.
- Vulnerabilities range from Medium to Critical severity, impacting multiple versions.
- Key themes include privilege escalation, unauthorized data access, and account takeover.
- Critical flaws like CVE-2026-86478 enable unauthenticated account takeover via YouTrack Helpdesk.
- Patches are available across various 2025 and 2026 versions of YouTrack.
On September 7, 2026, a significant batch of 22 vulnerabilities was disclosed for JetBrains YouTrack, impacting various versions of the issue tracking software. These vulnerabilities, ranging in severity from Low to Critical, were all published simultaneously, indicating a coordinated disclosure event. The disclosures highlight a broad range of security weaknesses, including privilege escalation, unauthorized data access, and potential account takeover.
Several vulnerabilities center on improper access control and permission checks. CVE-2026-86500, a Medium severity flaw, allowed users with project update permissions to grant themselves Project Admin rights due to a missing escalation check. Similarly, CVE-2026-86493 (Medium) enabled read-only users to create and modify whiteboard cards, while CVE-2026-86495 (Medium) permitted the creation of knowledge base articles in inaccessible projects. A critical vulnerability, CVE-2026-86478 (Critical, CVSSv3 9.8), involved improper authentication in YouTrack Helpdesk, allowing unauthenticated account takeover via a self-asserted email address. This vulnerability was patched in versions 2025.3.161254 and 2026.1.14042.
Data exposure and unauthorized modification were also prominent themes. CVE-2026-86499 (Medium) saw predefined search fields leaking all group names to any user. CVE-2026-86497 (Medium) allowed project administrators to exfiltrate stored mailbox credentials by changing a mailbox host without re-authentication. CVE-2026-86499 (Medium) and CVE-2026-86497 (Medium) were fixed in version 2026.2.18769. Furthermore, CVE-2026-86494 (High) enabled unauthorized changes to links on inaccessible issues when cloning a whiteboard, and CVE-2026-86489 (Medium) allowed the disclosure of private issues and starred folders across organizations via an IDOR in the user profile API. CVE-2026-86488 (Medium) also involved an IDOR, exposing private saved searches.
More severe issues included privilege escalation and token theft. CVE-2026-86482 (High, CVSSv3 8.8) allowed unchecked group membership changes to escalate privileges, patched in version 2026.2.18634. A particularly concerning vulnerability, CVE-2026-86492 (High, CVSSv3 8.5), involved a shared token cache that enabled cross-tenant theft of GitHub App installation tokens, also fixed in 2026.2.18634. Another high-severity flaw, CVE-2026-86479 (High, CVSSv3 8.1), involved missing authorization that allowed access to restricted REST API resources via IDOR, with patches in 2026.2.18788, 2026.1.14055, and 2025.3.161254.
Several cross-site scripting (XSS) vulnerabilities were also identified. CVE-2026-86491 (Low) allowed stored XSS via project and organization icon uploads. CVE-2026-86484 (Medium) exploited AngularJS template injection in assignee names, leading to stored XSS. Additionally, CVE-2026-86483 (Medium) enabled stored XSS via a custom field on Agile board cards.
Other vulnerabilities included issues with webhook handlers and authentication. CVE-2026-86486 (Low) detailed a generic VCS webhook handler that failed open when its secret was blank. CVE-2026-86485 (Low) described IP spoofing via HTTP headers that allowed forged Bitbucket webhooks. CVE-2026-86490 (Medium) involved improper permission checks that allowed overwriting of bundled apps via the app import endpoint. CVE-2026-86481 (Medium) allowed disclosure of restricted project icons through signed URL reuse. CVE-2026-86496 (Medium) involved missing access control on Helpdesk authorized reporters, exposing reporter email addresses. CVE-2026-86487 (Low) allowed read-only whiteboard users to modify canvas content via a crafted WebSocket message. CVE-2026-86498 (High) allowed modification of linked entities without update permission via pUT requests on link sub-resources.
The affected versions span multiple release lines, with patches distributed across 2025.3.160480, 2025.3.161254, 2026.1.14042, 2026.1.14047, 2026.1.14055, 2026.2.18634, 2026.2.18687, 2026.2.18769, and 2026.2.18788. Users are strongly advised to update to the patched versions to mitigate these widespread security risks.
This extensive disclosure underscores the importance of regular security audits and timely patching for complex software like JetBrains YouTrack. The variety of vulnerabilities suggests potential systemic issues that warrant ongoing attention from both the vendor and its user base. Staying informed about security advisories and applying updates promptly is crucial for maintaining the integrity and security of development workflows.