Exposure of Data Element to Wrong Session in YouTrack - CVE-2026-86492
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to exposure of data to the wrong session in the shared token cache when accessing cached GitHub App installation tokens. A remote user can retrieve GitHub App installation tokens associated with other tenants to disclose sensitive information.