Authorization Flaw in JetBrains YouTrack Allows Unauthorized Access to REST API Resources
CVE-2026-86479
8HIGH
What is CVE-2026-86479?
An authorization flaw in JetBrains YouTrack versions prior to 2026.2.18788 allows attackers to access restricted REST API resources. This security issue arises from an Insecure Direct Object Reference (IDOR), whereby the absence of proper authorization mechanisms permits unauthorized users to retrieve sensitive information via specific resource IDs. Users are advised to upgrade to the latest version to mitigate potential risks and secure their data.
Affected Version(s)
YouTrack 0 < 2026.2.18788, 2026.1.14055, 2025.3.161254