
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86500 is a privilege escalation vulnerability in JetBrains YouTrack caused by a missing escalation check that allows a user with project update permissions to grant themselves the Project Admin role. It affects all YouTrack versions before 2026.1.14047 and was published on September 7, 2026. The CVE was assigned by JetBrains and carries a CVSS v3.1 base score of 5.5 (Medium/Moderate) (GitHub Advisory, JetBrains).
The root cause is classified as CWE-266 (Incorrect Privilege Assignment): the application fails to enforce an authorization check when a user with project update permissions attempts to assign themselves a higher-privilege role (Project Admin). Because the escalation check is absent, the permission assignment API or UI endpoint does not validate whether the requesting user is authorized to elevate their own role, allowing the operation to succeed without additional approval. The attack vector is network-based, requires no user interaction, and requires only high-level (project update) privileges as a precondition (GitHub Advisory).
A user with project update permissions can escalate their own privileges to the Project Admin role without additional authorization, gaining full administrative control over the affected project. This could allow the attacker to modify project settings, manage other users' permissions within the project, access sensitive project data, and potentially pivot to broader administrative actions depending on the YouTrack deployment configuration. Availability is not directly impacted, but confidentiality and integrity of project data are both at low risk of compromise (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.15–0.16%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and SSVC assessment indicates it is not automatable and has only partial technical impact. Exploitation requires an authenticated account with at least project update permissions, limiting the attacker pool.
JetBrains has released a fix in YouTrack version 2026.1.14047. Organizations should update to this version or later as the primary remediation step (JetBrains, GitHub Advisory). As an interim measure, administrators should audit current project permission assignments — particularly users with project update permissions — and verify that no unauthorized privilege escalation has already occurred by reviewing Project Admin role assignments. Restricting project update permissions to only trusted users can reduce the attack surface until patching is complete.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."