Unauthorized Modification in JetBrains YouTrack
CVE-2026-86498
7.7HIGH
What is CVE-2026-86498?
In JetBrains YouTrack versions prior to 2025.3.160480 and 2026.1.14047, a vulnerability exists that allows users to send pUT requests on linked sub-resources. This flaw permits modifications to linked entities even when proper update permissions are not granted, potentially leading to unauthorized changes within the system. Users are advised to upgrade to the latest versions to mitigate this risk.
Affected Version(s)
YouTrack 0 < 2025.3.160480, 2026.1.14047