CVE-2026-86492: High severity JetBrains YouTrack vulnerability
Published Sep 7, 2026
·Updated
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
Affected Software
1 affected component
JetBrains YouTrack<2026.2.18634
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains YouTrackto a version that resolves this vulnerability.Fixed in 2026.2.18634
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments require remediation?
JetBrains YouTrack versions before 2026.2.18634 are affected. Upgrade to 2026.2.18634 or later.
2
What level of access does an attacker need?
The vulnerability is remotely reachable and requires low-privilege access. No user interaction is required.
3
What is the potential security impact?
Successful exploitation can expose GitHub App installation tokens across tenants. The reported impact includes high confidentiality impact and low integrity impact, with no availability impact.