Junglewise Threat Intelligence

CVE-2026-86481: JetBrains YouTrack signed URL reuse in project icon disclosure

CVE-2026-86481 · Severity: medium · CVSS 4.3 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a project tracking and issue management platform used by development teams. This vulnerability allows attackers to reuse signed URLs to access restricted project icons that should not be visible to them, potentially exposing sensitive project information or organizational structure details.

Technical details

The vulnerability is a signed URL reuse flaw in YouTrack's project icon access control mechanism. Attackers can intercept or obtain signed URLs intended for legitimate project icon access and reuse them repeatedly to retrieve icons from restricted projects they should not have permission to view. This occurs because the signed URLs lack proper scope binding or expiration enforcement specific to the requesting user or project context. The attack requires network access to YouTrack and likely requires authentication, but does not require special privileges. An attacker can enumerate and access unauthorized project icons, potentially disclosing project identities or organizational structure. The vulnerability was fixed in version 2026.2.18634 and later.

Affected products

  • JetBrains YouTrack before 2026.2.18634

Timeline

  • 2026-09-07: disclosed

References

Related threats