Cross-Tenant Vulnerability in JetBrains YouTrack Affecting GitHub App Installations
CVE-2026-86492

8.5HIGH

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86492?

A security flaw in JetBrains YouTrack prior to version 2026.2.18634 introduces a shared token cache that allows malicious users to exploit cross-tenant vulnerabilities, enabling unauthorized access to and theft of GitHub App installation tokens. This vulnerability raises significant concerns regarding the security of integrations in collaborative environments, emphasizing the need for updates and patches.

Affected Version(s)

YouTrack 0 < 2026.2.18634

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.