CVE-2026-86492
8.5JetBrains · YouTrack
A shared token cache in JetBrains YouTrack allows authenticated users to perform cross-tenant theft of GitHub App installation tokens.
Executive summary
A critical vulnerability in JetBrains YouTrack allows authenticated attackers to exfiltrate GitHub App installation tokens across tenant boundaries, posing a severe risk to supply chain security.
Vulnerability
The flaw is categorized as CWE-488 (Exposure of Sensitive Information Through Data Sharing), where an improper implementation of a shared token cache allows a low-privileged authenticated user to access tokens belonging to other tenants.
Business impact
The ability for an attacker to steal GitHub App installation tokens enables unauthorized access to external source code repositories and CI/CD pipelines associated with those tokens. This could lead to massive intellectual property theft, injection of malicious code into downstream software, and a complete compromise of development workflows. Given the CVSS score of 8.5, this high-severity issue necessitates immediate attention to prevent potential supply chain attacks.
Remediation
Immediate Action: Upgrade JetBrains YouTrack to version 2026.2.18634 or later to resolve the shared cache vulnerability.
Proactive Monitoring: Review access logs for unusual patterns of GitHub App token usage or unauthorized attempts to access cross-tenant configurations.
Compensating Controls: Implement strict identity and access management policies for GitHub Apps and consider rotating existing installation tokens if there is any suspicion of unauthorized access.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The vulnerability presents a significant risk to organizations leveraging YouTrack for integrated development workflows. Administrators should prioritize the update to version 2026.2.18634 immediately to eliminate the possibility of token theft. Failure to patch may result in the compromise of sensitive credentials that grant access to your organization's broader development ecosystem.
More JetBrains CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section