ZeroHour

CVE-2026-86479

large

Missing Authorization (IDOR) in JetBrains YouTrack REST API exposes restricted data

CVSS 3.1
8.1 high
EPSS
<1%p10
Published
()
Modified
AI analysis

JetBrains YouTrack, JetBrains' issue-tracking and project-management server, contained REST API endpoints that failed to enforce authorization checks on restricted resources (CWE-862, missing authorization). An authenticated, low-privileged user could exploit this over the network with no user interaction by manipulating resource identifiers in REST requests (IDOR) to reach restricted REST API resources outside their permitted scope. Per the CVSS 3.1 vector, successful abuse carries high confidentiality and integrity impact with no availability impact, meaning an attacker could gain unauthorized access to restricted data and potentially alter it. All YouTrack deployments running builds earlier than the fixed builds for their release branch — 2025.3.161254, 2026.1.14055, and 2026.2.18788 — are affected. No public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days, so no exploitation is currently known.

What to do: Upgrade YouTrack to at least 2026.2.18788, 2026.1.14055, or 2025.3.161254, depending on your release branch. Because this is an authorization flaw, patching is the primary remediation; until you patch, limit network exposure of the YouTrack REST API to trusted users and networks. After upgrading, review access logs for REST API requests that touched resources outside the requesting users' project or permission scope.

Affected
JetBrains YouTrackAll builds prior to the fixed builds 2025.3.161254, 2026.1.14055, and 2026.2.18788 (the respective fix versions for the 2025.3, 2026.1, and 2026.2 release branc
Estimated exposure
large≈ tens of thousands of deployments (self-hosted servers plus cloud tenants), plausibly 100,000+ users — YouTrack is a long-standing, widely adopted commercial issue tracker available both self-hosted and as a JetBrains-hosted cloud service; public internet scans typically show thousands of exposed instances, and typical organizational…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.