Authorization bypass through user-controlled key in YouTrack - CVE-2026-86481
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose restricted project icons.
The vulnerability exists due to authorization bypass through a user-controlled key in signed URL handling for project icons when reusing a signed URL for a restricted project icon. A remote attacker can reuse a signed URL to disclose restricted project icons.