CVE-2026-86488: Medium severity JetBrains YouTrack vulnerability
In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains YouTrackto a version that resolves this vulnerability.Fixed in 2026.2.18634 - Compensating control
Mitigate exposure of the watchRules and issueListConfig endpoints by restricting network access to these endpoints until you upgrade to JetBrains YouTrack 2026.2.18634 or later.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs network access to the affected YouTrack instance and low-privileged authenticated access. No user interaction is required.
What data is exposed if exploitation succeeds?
The issue can expose private saved searches through the watchRules and issueListConfig endpoints. The available data indicates confidentiality impact only; integrity and availability are not affected.
Which installations are affected?
JetBrains YouTrack versions before 2026.2.18634 are affected. The provided information does not state whether any particular default configuration changes exposure.