CVE-2026-86479
largeMissing Authorization (IDOR) in JetBrains YouTrack REST API exposes restricted data
JetBrains YouTrack, JetBrains' issue-tracking and project-management server, contained REST API endpoints that failed to enforce authorization checks on restricted resources (CWE-862, missing authorization). An authenticated, low-privileged user could exploit this over the network with no user interaction by manipulating resource identifiers in REST requests (IDOR) to reach restricted REST API resources outside their permitted scope. Per the CVSS 3.1 vector, successful abuse carries high confidentiality and integrity impact with no availability impact, meaning an attacker could gain unauthorized access to restricted data and potentially alter it. All YouTrack deployments running builds earlier than the fixed builds for their release branch — 2025.3.161254, 2026.1.14055, and 2026.2.18788 — are affected. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days, so no exploitation is currently known.
What to do: Upgrade YouTrack to at least 2026.2.18788, 2026.1.14055, or 2025.3.161254, depending on your release branch. Because this is an authorization flaw, patching is the primary remediation; until you patch, limit network exposure of the YouTrack REST API to trusted users and networks. After upgrading, review access logs for REST API requests that touched resources outside the requesting users' project or permission scope.
| JetBrains YouTrack | All builds prior to the fixed builds 2025.3.161254, 2026.1.14055, and 2026.2.18788 (the respective fix versions for the 2025.3, 2026.1, and 2026.2 release branc |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.