CVE-2026-86494

7.7

JetBrains · YouTrack

JetBrains YouTrack prior to 2026.2.18634 contains a flaw where cloning a whiteboard permits unauthorized modifications to links on issues that the user should not be able to access.

Executive summary

An authenticated user in JetBrains YouTrack can perform unauthorized modifications to links on restricted issues by cloning a whiteboard, presenting a risk to data integrity.

Vulnerability

This is an improper authorization vulnerability (CWE-862) occurring within the whiteboard cloning function, which allows a low-privileged authenticated user to bypass access controls.

Business impact

The ability for unauthorized users to modify links on inaccessible issues undermines the confidentiality and integrity of sensitive project tracking data. Given the CVSS score of 7.7, this vulnerability poses a significant risk to organizations relying on YouTrack for managing proprietary or restricted project information, as it could lead to the exposure or corruption of internal issue relationships.

Remediation

Immediate Action: Update JetBrains YouTrack to version 2026.2.18634 or later to resolve the underlying authorization flaw.

Proactive Monitoring: Review application access logs for unusual patterns involving whiteboard cloning actions or unauthorized link modifications.

Compensating Controls: Restrict permissions for whiteboard creation and cloning to trusted users while the patch is being deployed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a high-severity authorization failure that allows users to perform actions exceeding their assigned permissions. Administrators should prioritize the update to version 2026.2.18634 immediately to ensure that restricted data remains protected from unauthorized modification.

More JetBrains CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources