Junglewise Threat Intelligence

CVE-2026-86492: JetBrains YouTrack cross-tenant GitHub App token theft

CVE-2026-86492 · Severity: high · CVSS 8.5 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a project tracking and issue management system used by development teams. A flaw in its GitHub integration allowed attackers on one tenant (customer instance) to steal GitHub App installation tokens from other tenants, potentially granting unauthorized access to repositories and sensitive source code across multiple organizations.

Technical details

YouTrack uses a shared token cache for GitHub App installation tokens without proper tenant isolation. An attacker with access to one YouTrack tenant instance could retrieve cached tokens belonging to other tenants, bypassing authentication and authorization controls. The vulnerability affects YouTrack versions before 2026.2.18634. This is a cross-tenant data exposure issue resulting from insufficient cache compartmentalization. The issue has been patched in version 2026.2.18634 and later.

Affected products

  • JetBrains YouTrack before 2026.2.18634

Timeline

  • 2026-09-07: disclosed
  • 2026-02-18: patched: Fixed in YouTrack 2026.2.18634 and later

References

Related threats