CVE-2026-86482
largeUnchecked group membership changes in JetBrains YouTrack allow privilege escalation
CVE-2026-86482 is an incorrect privilege assignment flaw (CWE-266) in JetBrains YouTrack in which changes to user group membership are not properly authorization-checked. A low-privileged, authenticated user can trigger the issue over the network (no user interaction required) by issuing group membership changes, such as adding accounts to more privileged groups. This allows the attacker to escalate to a higher-privileged role, with high impact on the confidentiality, integrity, and availability of the YouTrack instance. Any YouTrack deployment running a version before 2026.2.18634 is affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently puts the 30-day exploitation probability at about 0.2%.
What to do: Upgrade YouTrack to version 2026.2.18634 or later. Until patched, restrict which accounts can modify user group memberships and audit recent membership changes, especially additions to administrator or other privileged groups, to detect unauthorized privilege grants. Check user accounts for elevated roles they did not legitimately receive.
| JetBrains YouTrack | before 2026.2.18634 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
- Weakness
- CWE-266
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.