
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86495 is a missing authorization vulnerability in JetBrains YouTrack that allows authenticated users to create knowledge base articles in projects they do not have access to. It affects all YouTrack versions before 2026.2.18687 and was published on September 7, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), assigned by JetBrains (GitHub Advisory, JetBrains).
The root cause is classified as CWE-862 (Missing Authorization): the application fails to perform adequate permission checks when an authenticated user attempts to create knowledge base articles, allowing them to write content into projects they are not authorized to access. The attack vector is network-based, requires low privileges (any authenticated account), no user interaction, and low attack complexity. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory).
Successful exploitation allows any authenticated YouTrack user to bypass project-level access controls and create knowledge base articles in otherwise inaccessible projects, resulting in a high integrity impact. There is no confidentiality or availability impact — attackers cannot read restricted data or disrupt service, but they can inject unauthorized content into sensitive project knowledge bases. This could be used to spread misinformation, pollute documentation, or potentially facilitate social engineering within an organization (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept for this vulnerability. The EPSS score is approximately 0.17–0.19%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD SSVC assessment notes exploitation as "none" and the attack as non-automatable (GitHub Advisory).
JetBrains has released a fix in YouTrack version 2026.2.18687; upgrading to this version or later is the recommended remediation. As interim measures, administrators should implement network-level access controls to restrict YouTrack access to authorized users only, and audit all knowledge base articles across projects to identify any unauthorized content that may have been created prior to patching (JetBrains, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."