Cross-Tenant Vulnerability in JetBrains YouTrack Affecting GitHub App Installations
CVE-2026-86492
8.5HIGH
What is CVE-2026-86492?
A security flaw in JetBrains YouTrack prior to version 2026.2.18634 introduces a shared token cache that allows malicious users to exploit cross-tenant vulnerabilities, enabling unauthorized access to and theft of GitHub App installation tokens. This vulnerability raises significant concerns regarding the security of integrations in collaborative environments, emphasizing the need for updates and patches.
Affected Version(s)
YouTrack 0 < 2026.2.18634