Predefined Search Field Information Leak in JetBrains YouTrack
CVE-2026-86499
4.3MEDIUM
What is CVE-2026-86499?
JetBrains YouTrack prior to version 2026.1.14047 contains a vulnerability that allows any user to access predefined search fields, inadvertently leaking all group names. This exposure occurs irrespective of the user's visibility permissions, posing significant risks to user privacy and data security. Organizations using this tool should update to the latest version promptly to mitigate the risk of unauthorized information exposure.
Affected Version(s)
YouTrack 0 < 2026.1.14047