CVE-2026-86479: High severity JetBrains YouTrack vulnerability
In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains YouTrackto a version that resolves this vulnerability.Fixed in 2026.2.18788
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker needs low-privileged access to YouTrack. No user interaction is required, and the issue can be exploited remotely over the network.
What is the impact if exploitation succeeds?
The missing authorization checks can allow access to restricted REST API resources through an insecure direct object reference. This can result in high-impact confidentiality and integrity compromise; availability impact is not indicated.
Which YouTrack releases contain fixes?
The issue is fixed in YouTrack 2026.2.18788, 2026.1.14055, and 2025.3.161254. Versions earlier than these listed releases are affected.