Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-86495
YouTrack vulnerability analysis and mitigation

Overview

CVE-2026-86495 is a missing authorization vulnerability in JetBrains YouTrack that allows authenticated users to create knowledge base articles in projects they do not have access to. It affects all YouTrack versions before 2026.2.18687 and was published on September 7, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), assigned by JetBrains (GitHub Advisory, JetBrains).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): the application fails to perform adequate permission checks when an authenticated user attempts to create knowledge base articles, allowing them to write content into projects they are not authorized to access. The attack vector is network-based, requires low privileges (any authenticated account), no user interaction, and low attack complexity. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory).

Impact

Successful exploitation allows any authenticated YouTrack user to bypass project-level access controls and create knowledge base articles in otherwise inaccessible projects, resulting in a high integrity impact. There is no confidentiality or availability impact — attackers cannot read restricted data or disrupt service, but they can inject unauthorized content into sensitive project knowledge bases. This could be used to spread misinformation, pollute documentation, or potentially facilitate social engineering within an organization (GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept for this vulnerability. The EPSS score is approximately 0.17–0.19%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment notes exploitation as "none" and the attack as non-automatable (GitHub Advisory).

Indicators of compromise

  • Logs: Unexpected knowledge base article creation events in YouTrack audit logs attributed to users who lack project membership or access rights.
  • Application Activity: Knowledge base articles appearing in restricted or inaccessible projects authored by accounts with no legitimate project role.
  • User Behavior: Authenticated low-privilege accounts performing article creation API calls against project IDs outside their assigned scope.

Mitigation and workarounds

JetBrains has released a fix in YouTrack version 2026.2.18687; upgrading to this version or later is the recommended remediation. As interim measures, administrators should implement network-level access controls to restrict YouTrack access to authorized users only, and audit all knowledge base articles across projects to identify any unauthorized content that may have been created prior to patching (JetBrains, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related YouTrack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86497MEDIUM6.8
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86495MEDIUM6.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86500MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86499MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86496MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management