Junglewise Threat Intelligence

CVE-2026-86487: JetBrains YouTrack WebSocket privilege escalation in whiteboard

CVE-2026-86487 · Severity: low · CVSS 3.1 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a project management and issue tracking system. A vulnerability in the whiteboard feature allowed users with read-only access to modify canvas content through crafted WebSocket messages, bypassing intended access controls and potentially corrupting or tampering with shared project work.

Technical details

This vulnerability is a privilege escalation / access control bypass in YouTrack's whiteboard WebSocket handling. Read-only whiteboard users could craft malicious WebSocket messages to modify canvas content that should have been restricted. The vulnerability requires network access to YouTrack and an authenticated session as a read-only whiteboard user. A successful exploit allows an attacker with limited permissions to modify collaborative whiteboard content, violating access control policies. The issue is fixed in YouTrack version 2026.2.18634 and later.

Affected products

  • JetBrains YouTrack before 2026.2.18634

Timeline

  • 2026-09-07: disclosed

References

Related threats