CVE-2026-86492
moderateCross-tenant token cache leak in JetBrains YouTrack exposes GitHub App tokens
JetBrains YouTrack before 2026.2.18634 stored GitHub App installation tokens in a shared cache that lacked proper per-tenant isolation (CWE-488), allowing tokens issued to one tenant to be exposed to another. A network-adjacent or remote authenticated user with low privileges could trigger the cross-tenant read without user interaction, given the shared cache design. An attacker who obtains these installation tokens gains access to the victim tenant's GitHub App installation with its granted permissions, causing high-confidentiality impact and limited integrity impact via the GitHub API. All YouTrack deployments running versions before 2026.2.18634 that use the GitHub App integration are affected, including multi-tenant or shared-instance setups. There is no public proof of concept, the issue is not in CISA KEV, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days, so exploitation is not currently confirmed.
What to do: Upgrade YouTrack to 2026.2.18634 or later. Operators of instances using the GitHub App integration should review audit logs for unexpected cross-tenant token access and consider rotating or re-authorizing GitHub App installation tokens as a precaution. Where multi-tenant or shared deployments are in use, verify after patching that tokens are segregated per tenant.
| JetBrains YouTrack | all versions before 2026.2.18634 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
- Weakness
- CWE-488
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.