CVE-2026-86490: Medium severity JetBrains YouTrack vulnerability
Published Sep 7, 2026
·Updated
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint
Affected Software
1 affected component
JetBrains YouTrack<2026.2.18634
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The attack requires low-level privileges. It can be performed over the network with low attack complexity and does not require user interaction.
2
What is the likely security impact?
The vulnerability affects integrity by allowing bundled apps to be overwritten through the app import endpoint. The provided CVSS vector indicates no confidentiality or availability impact.
3
How can I determine whether an installation is affected?
JetBrains YouTrack versions before 2026.2.18634 are affected. Installations running 2026.2.18634 or later are not identified as affected by the provided data.