ZeroHour

CVE-2026-86492

moderate

Cross-tenant token cache leak in JetBrains YouTrack exposes GitHub App tokens

CVSS 3.1
8.5 high
EPSS
<1%p45
Published
()
Modified
AI analysis

JetBrains YouTrack before 2026.2.18634 stored GitHub App installation tokens in a shared cache that lacked proper per-tenant isolation (CWE-488), allowing tokens issued to one tenant to be exposed to another. A network-adjacent or remote authenticated user with low privileges could trigger the cross-tenant read without user interaction, given the shared cache design. An attacker who obtains these installation tokens gains access to the victim tenant's GitHub App installation with its granted permissions, causing high-confidentiality impact and limited integrity impact via the GitHub API. All YouTrack deployments running versions before 2026.2.18634 that use the GitHub App integration are affected, including multi-tenant or shared-instance setups. There is no public proof of concept, the issue is not in CISA KEV, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days, so exploitation is not currently confirmed.

What to do: Upgrade YouTrack to 2026.2.18634 or later. Operators of instances using the GitHub App integration should review audit logs for unexpected cross-tenant token access and consider rotating or re-authorizing GitHub App installation tokens as a precaution. Where multi-tenant or shared deployments are in use, verify after patching that tokens are segregated per tenant.

Affected
JetBrains YouTrackall versions before 2026.2.18634
Estimated exposure
moderateroughly thousands of YouTrack instances, of which only those using the GitHub App integration are actually exposed (estimate, no authoritative install count… — YouTrack is a commercial issue tracker with a self-hosted/InCloud install base plausibly in the low tens of thousands, but the flaw only matters for deployments with the GitHub App integration, pointing to an order of 1k-10k affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

Weakness
CWE-488
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.