ZeroHour

CVE-2026-86482

large

Unchecked group membership changes in JetBrains YouTrack allow privilege escalation

CVSS 3.1
8.8 high
EPSS
<1%p14
Published
()
Modified
AI analysis

CVE-2026-86482 is an incorrect privilege assignment flaw (CWE-266) in JetBrains YouTrack in which changes to user group membership are not properly authorization-checked. A low-privileged, authenticated user can trigger the issue over the network (no user interaction required) by issuing group membership changes, such as adding accounts to more privileged groups. This allows the attacker to escalate to a higher-privileged role, with high impact on the confidentiality, integrity, and availability of the YouTrack instance. Any YouTrack deployment running a version before 2026.2.18634 is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently puts the 30-day exploitation probability at about 0.2%.

What to do: Upgrade YouTrack to version 2026.2.18634 or later. Until patched, restrict which accounts can modify user group memberships and audit recent membership changes, especially additions to administrator or other privileged groups, to detect unauthorized privilege grants. Check user accounts for elevated roles they did not legitimately receive.

Affected
JetBrains YouTrackbefore 2026.2.18634
Estimated exposure
largetens of thousands of internet-exposed self-hosted instances (order of magnitude ≈10k–100k), plus an unknown number of JetBrains-hosted cloud tenants — YouTrack is a widely deployed web issue tracker whose self-hosted instances are typically exposed to the internet by design, and public internet scans have long shown tens of thousands of reachable YouTrack servers, while cloud tenant…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation

Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.