CVE-2026-86498: High severity JetBrains YouTrack vulnerability
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains YouTrackto a version that resolves this vulnerability.Fixed in 2025.3.160480
Event History
Frequently Asked Questions
Which YouTrack installations are affected?
JetBrains YouTrack versions before 2025.3.160480 and before 2026.1.14047 are affected. Installations at or beyond those listed versions are not identified as affected by the provided information.
What level of access does an attacker need?
The attack requires low privileges and can be performed over the network. It does not require user interaction, and the attack complexity is rated low.
What is the impact of successful exploitation?
An attacker could use PUT requests to link sub-resources to modify linked entities without having update permission. The provided vector indicates high integrity impact, no confidentiality impact, and no availability impact.