Missing Authorization in YouTrack - CVE-2026-86495
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to create knowledge base articles in inaccessible projects.
The vulnerability exists due to missing permission checks in knowledge base article creation when creating knowledge base articles. A remote user can submit article creation requests to create knowledge base articles in inaccessible projects.