Unauthorized Link Modification in JetBrains YouTrack
CVE-2026-86494

7.7HIGH

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86494?

In JetBrains YouTrack prior to version 2026.2.18634, an issue was identified where cloning a whiteboard could lead to unauthorized alterations of links connected to inaccessible issues. This flaw exposes the application to potential misuse, allowing unauthorized users to manipulate links that they should not have access to, thereby compromising the integrity and confidentiality of issue tracking within the platform.

Affected Version(s)

YouTrack 0 < 2026.2.18634

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.