Authorization bypass through user-controlled key in YouTrack - CVE-2026-86489
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose private issues and starred folders across organizations.
The vulnerability exists due to improper authorization in the user profile API when accessing user profile API endpoints with manipulated identifiers. A remote attacker can manipulate identifiers in user profile API requests to disclose private issues and starred folders across organizations.