ZeroHour

CVE-2026-86494

moderate

Missing authorization in JetBrains YouTrack lets whiteboard clones edit restricted issues

CVSS 3.1
7.7 high
EPSS
<1%p7
Published
()
Modified
AI analysis

JetBrains YouTrack before 2026.2.18634 contains a missing-authorization flaw (CWE-862) in its whiteboard feature: cloning a whiteboard can modify links on issues the user has no permission to access. An attacker needs only a low-privileged authenticated account; by cloning a whiteboard whose cards reference restricted issues, they trigger link changes on those issues without any permission check being enforced. The impact is integrity-only (CVSS 3.1 shows no confidentiality or availability impact, high integrity): the attacker can alter links on issues they otherwise cannot read or edit, but cannot view their contents. Any organization running an affected YouTrack version where users with differing issue permissions share whiteboards is exposed, whether the tool is self-hosted or run as a JetBrains-hosted service. No public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.2%, 7th percentile) indicate no known exploitation to date.

What to do: Upgrade YouTrack to version 2026.2.18634 or later. Since exploitation requires an authenticated account and only tampers with issue links, audit recent link changes on permission-restricted issues for unexpected edits by low-privileged users, and prioritize patching multi-user instances where whiteboards are shared across permission boundaries.

Affected
JetBrains YouTrackAll versions before 2026.2.18634 (fixed in 2026.2.18634)
Estimated exposure
moderate≈ tens of thousands of users across likely low thousands of YouTrack deployments, with only a few thousand instances internet-exposed (estimate; no install… — No install counts were provided, so this is estimated from YouTrack's deployment patterns as a team-oriented issue tracker with a far smaller footprint than market leaders like Jira, where most instances are internal-facing and public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.