Authorization bypass through user-controlled key in YouTrack - CVE-2026-86489

 

Authorization bypass through user-controlled key in YouTrack - CVE-2026-86489

Published: September 7, 2026


Vulnerability identifier: #VU147350
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-86489
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose private issues and starred folders across organizations.

The vulnerability exists due to improper authorization in the user profile API when accessing user profile API endpoints with manipulated identifiers. A remote attacker can manipulate identifiers in user profile API requests to disclose private issues and starred folders across organizations.


Affected software

YouTrack

How to mitigate CVE-2026-86489

Install security update from vendor's website.

YouTrack - update to 2026.2.18634

External References

Related Security Bulletins