Unauthorized Modification in JetBrains YouTrack
CVE-2026-86498

7.7HIGH

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86498?

In JetBrains YouTrack versions prior to 2025.3.160480 and 2026.1.14047, a vulnerability exists that allows users to send pUT requests on linked sub-resources. This flaw permits modifications to linked entities even when proper update permissions are not granted, potentially leading to unauthorized changes within the system. Users are advised to upgrade to the latest versions to mitigate this risk.

Affected Version(s)

YouTrack 0 < 2025.3.160480, 2026.1.14047

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.