Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-86500
YouTrack vulnerability analysis and mitigation

Overview

CVE-2026-86500 is a privilege escalation vulnerability in JetBrains YouTrack caused by a missing escalation check that allows a user with project update permissions to grant themselves the Project Admin role. It affects all YouTrack versions before 2026.1.14047 and was published on September 7, 2026. The CVE was assigned by JetBrains and carries a CVSS v3.1 base score of 5.5 (Medium/Moderate) (GitHub Advisory, JetBrains).

Technical details

The root cause is classified as CWE-266 (Incorrect Privilege Assignment): the application fails to enforce an authorization check when a user with project update permissions attempts to assign themselves a higher-privilege role (Project Admin). Because the escalation check is absent, the permission assignment API or UI endpoint does not validate whether the requesting user is authorized to elevate their own role, allowing the operation to succeed without additional approval. The attack vector is network-based, requires no user interaction, and requires only high-level (project update) privileges as a precondition (GitHub Advisory).

Impact

A user with project update permissions can escalate their own privileges to the Project Admin role without additional authorization, gaining full administrative control over the affected project. This could allow the attacker to modify project settings, manage other users' permissions within the project, access sensitive project data, and potentially pivot to broader administrative actions depending on the YouTrack deployment configuration. Availability is not directly impacted, but confidentiality and integrity of project data are both at low risk of compromise (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.15–0.16%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and SSVC assessment indicates it is not automatable and has only partial technical impact. Exploitation requires an authenticated account with at least project update permissions, limiting the attacker pool.

Exploitation steps

  1. Reconnaissance: Identify a JetBrains YouTrack instance running a version prior to 2026.1.14047, accessible over the network.
  2. Obtain project update permissions: Log in with an account that has been granted project update permissions on a target project (or compromise such an account).
  3. Trigger privilege escalation: Use the YouTrack UI or API to modify project role assignments, specifically assigning the Project Admin role to the attacker's own account — an action that should normally be restricted but is not properly checked.
  4. Achieve Project Admin access: With the escalated role, the attacker gains full administrative control over the project, including managing members, settings, and sensitive project data (GitHub Advisory).

Indicators of compromise

  • Logs: YouTrack audit logs showing a user with project update permissions assigning themselves the Project Admin role without a corresponding approval or admin action.
  • Logs: Unexpected role change events in YouTrack's activity or audit trail, particularly self-assignment of elevated roles.
  • Application Behavior: Users appearing in the Project Admin role who were not explicitly granted that role by a system administrator.

Mitigation and workarounds

JetBrains has released a fix in YouTrack version 2026.1.14047. Organizations should update to this version or later as the primary remediation step (JetBrains, GitHub Advisory). As an interim measure, administrators should audit current project permission assignments — particularly users with project update permissions — and verify that no unauthorized privilege escalation has already occurred by reviewing Project Admin role assignments. Restricting project update permissions to only trusted users can reduce the attack surface until patching is complete.

Additional resources


SourceThis report was generated using AI

Related YouTrack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86497MEDIUM6.8
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86495MEDIUM6.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86500MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86499MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86496MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management