Authorization Flaw in JetBrains YouTrack Allows Unauthorized Access to REST API Resources
CVE-2026-86479

8HIGH

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86479?

An authorization flaw in JetBrains YouTrack versions prior to 2026.2.18788 allows attackers to access restricted REST API resources. This security issue arises from an Insecure Direct Object Reference (IDOR), whereby the absence of proper authorization mechanisms permits unauthorized users to retrieve sensitive information via specific resource IDs. Users are advised to upgrade to the latest version to mitigate potential risks and secure their data.

Affected Version(s)

YouTrack 0 < 2026.2.18788, 2026.1.14055, 2025.3.161254

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.