Access Control Flaw in JetBrains YouTrack Exposes Reporter Email Addresses
CVE-2026-86496
4.3MEDIUM
What is CVE-2026-86496?
An access control vulnerability in JetBrains YouTrack prior to version 2026.2.18769 allows unauthorized exposure of reporter email addresses. This issue results from insufficient access controls, posing a risk to the privacy of authorized reporters' information. Organizations using older versions of YouTrack should evaluate their security posture and consider upgrading to protect sensitive data.
Affected Version(s)
YouTrack 0 < 2026.2.18769