Missing Authorization in YouTrack - CVE-2026-86479
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to access restricted REST API resources.
The vulnerability exists due to missing authorization in restricted REST API resources when processing requests that reference resource identifiers. A remote user can send a request referencing a restricted resource identifier to access restricted REST API resources.