CVE-2026-86494
moderateMissing authorization in JetBrains YouTrack lets whiteboard clones edit restricted issues
JetBrains YouTrack before 2026.2.18634 contains a missing-authorization flaw (CWE-862) in its whiteboard feature: cloning a whiteboard can modify links on issues the user has no permission to access. An attacker needs only a low-privileged authenticated account; by cloning a whiteboard whose cards reference restricted issues, they trigger link changes on those issues without any permission check being enforced. The impact is integrity-only (CVSS 3.1 shows no confidentiality or availability impact, high integrity): the attacker can alter links on issues they otherwise cannot read or edit, but cannot view their contents. Any organization running an affected YouTrack version where users with differing issue permissions share whiteboards is exposed, whether the tool is self-hosted or run as a JetBrains-hosted service. No public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.2%, 7th percentile) indicate no known exploitation to date.
What to do: Upgrade YouTrack to version 2026.2.18634 or later. Since exploitation requires an authenticated account and only tampers with issue links, audit recent link changes on permission-restricted issues for unexpected edits by low-privileged users, and prioritize patching multi-user instances where whiteboards are shared across permission boundaries.
| JetBrains YouTrack | All versions before 2026.2.18634 (fixed in 2026.2.18634) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.