CVE-2026-86500: Medium severity JetBrains YouTrack vulnerability
In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains YouTrackto a version that resolves this vulnerability.Fixed in 2026.1.14047
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user who already has project update permissions can exploit it. The issue does not apply to users without that permission.
What access can an attacker gain?
The user can grant themselves the Project Admin role for the affected project. This can expose project-level administrative capabilities beyond their intended privileges.
Which versions are affected?
JetBrains YouTrack versions before 2026.1.14047 are affected. Upgrading to 2026.1.14047 or later addresses the issue.
What can be done before upgrading?
Review and restrict project update permissions to trusted users, since that permission is required for exploitation. Also review project role assignments for unexpected Project Admin grants.