SB20260907135 - Multiple vulnerabilities in YouTrack
Published: September 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 14 vulnerabilities.
1) Missing Authentication for Critical Function (CVE-ID: CVE-2026-86486)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to submit unauthenticated webhook requests.
The vulnerability exists due to missing authentication in the generic VCS webhook handler when its secret is blank. A remote attacker can send a webhook request without providing a valid secret to submit unauthenticated webhook requests.
2) Reliance on IP Address for Authentication (CVE-ID: CVE-2026-86485)
CWE-ID: CWE-291 - Reliance on IP Address for Authentication
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to forge Bitbucket webhooks.
The vulnerability exists due to improper validation of source IP addresses in Bitbucket webhook handling when sending HTTP requests with spoofed IP headers. A remote attacker can send HTTP requests with spoofed IP headers to forge Bitbucket webhooks.
3) Cross-site scripting (CVE-ID: CVE-2026-86484)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary script in a victim\'s browser.
The vulnerability exists due to improper neutralization of AngularJS template expressions in assignee names when rendering assignee names. A remote attacker can inject a malicious AngularJS template into an assignee name to execute arbitrary script in a victim\'s browser.
User interaction is required to view content containing the affected assignee name.
4) Cross-site scripting (CVE-ID: CVE-2026-86483)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in a victim\'s browser.
The vulnerability exists due to stored cross-site scripting in custom fields on Agile board cards when displaying an Agile board card containing a crafted custom field. A remote user can inject a malicious script into a custom field to execute arbitrary script in a victim\'s browser.
User interaction is required to view the affected Agile board card.
5) Incorrect Privilege Assignment (CVE-ID: CVE-2026-86482)
CWE-ID: CWE-266 - Incorrect Privilege Assignment
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper privilege management in group membership management when modifying group memberships. A remote user can make unchecked group membership changes to escalate privileges.
6) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-86481)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose restricted project icons.
The vulnerability exists due to authorization bypass through a user-controlled key in signed URL handling for project icons when reusing a signed URL for a restricted project icon. A remote attacker can reuse a signed URL to disclose restricted project icons.
7) Missing Authorization (CVE-ID: CVE-2026-86494)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify links on inaccessible issues without authorization.
The vulnerability exists due to improper authorization in the whiteboard cloning feature when cloning a whiteboard. A remote user can clone a whiteboard to modify links on inaccessible issues without authorization.
8) Incorrect authorization (CVE-ID: CVE-2026-86493)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to create and modify whiteboard cards.
The vulnerability exists due to improper authorization in whiteboard cards when handling card creation and modification actions from read-only users. A remote user can submit card creation or modification requests to create and modify whiteboard cards.
9) Exposure of Data Element to Wrong Session (CVE-ID: CVE-2026-86492)
CWE-ID: CWE-488 - Exposure of Data Element to Wrong Session
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to exposure of data to the wrong session in the shared token cache when accessing cached GitHub App installation tokens. A remote user can retrieve GitHub App installation tokens associated with other tenants to disclose sensitive information.
10) Cross-site scripting (CVE-ID: CVE-2026-86491)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary JavaScript in a user\'s browser.
The vulnerability exists due to stored cross-site scripting in the project and organization icon upload functionality when uploading a crafted icon file. A remote user can upload an icon file containing malicious script to execute arbitrary JavaScript in the browser of a user who views the uploaded icon.
11) Incorrect authorization (CVE-ID: CVE-2026-86490)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to overwrite bundled apps.
The vulnerability exists due to improper authorization in the app import endpoint when importing an app. A remote user can import an app to overwrite bundled apps.
12) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-86489)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose private issues and starred folders across organizations.
The vulnerability exists due to improper authorization in the user profile API when accessing user profile API endpoints with manipulated identifiers. A remote attacker can manipulate identifiers in user profile API requests to disclose private issues and starred folders across organizations.
13) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-86488)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose private saved searches.
The vulnerability exists due to improper authorization in the watchRules and issueListConfig endpoints when accessing saved searches. A remote attacker can access private saved searches through these endpoints to disclose private saved searches.
14) Incorrect authorization (CVE-ID: CVE-2026-86487)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify canvas content.
The vulnerability exists due to improper authorization in whiteboard WebSocket message handling when processing a crafted WebSocket message. A remote user can send a crafted WebSocket message to modify canvas content.
Remediation
Install update from vendor's website.
References
- https://www.jetbrains.com/privacy-security/issues-fixed/#05a309928542908e41d354207ef638c3
- https://www.jetbrains.com/privacy-security/issues-fixed/#79030293da0a5fe7e63d8c6a87926e4d
- https://www.jetbrains.com/privacy-security/issues-fixed/#7e24acac99804b2e172d06f66578f707
- https://www.jetbrains.com/privacy-security/issues-fixed/#53d7f9b3d8e3bad14cf3dd0ffdf9f438
- https://www.jetbrains.com/privacy-security/issues-fixed/#19403b052b8b6dec69133dd15460753f
- https://www.jetbrains.com/privacy-security/issues-fixed/#2d2ada21a02c78ebc4c288e8d352d237
- https://www.jetbrains.com/privacy-security/issues-fixed/#7dd1955e7f9c2e27e31f722da883b618
- https://www.jetbrains.com/privacy-security/issues-fixed/#98ee1b66dd34430d48c4f132a3c5550a
- https://www.jetbrains.com/privacy-security/issues-fixed/#e9ca5dfbac5e06e59d22321f7b70cd99
- https://www.jetbrains.com/privacy-security/issues-fixed/#ff9c3c6be7e19bc2402a9648334958cc
- https://www.jetbrains.com/privacy-security/issues-fixed/#8586fbd995a3c507fd74cce1804bd121
- https://www.jetbrains.com/privacy-security/issues-fixed/#2e24d7542bb77e2a79ff5b098ca94a03
- https://www.jetbrains.com/privacy-security/issues-fixed/#076d9fa477fbebcda68b4d9a877a20d4
- https://www.jetbrains.com/privacy-security/issues-fixed/#510657574b0efd46a75cdd3750501a4c