Junglewise Threat Intelligence

CVE-2026-86494: JetBrains YouTrack unauthorized link modification via whiteboard clone

CVE-2026-86494 · Severity: high · CVSS 7.7 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a web-based project management and issue tracking platform used by development teams. A vulnerability in its whiteboard feature allows attackers to clone whiteboards and gain unauthorized access to modify links associated with issues that should be inaccessible to them, potentially exposing sensitive project data or altering important issue references.

Technical details

The vulnerability exists in YouTrack versions before 2026.2.18634 and is triggered when cloning a whiteboard. The flaw allows an attacker to bypass access controls and modify links on issues that are otherwise restricted or inaccessible to the attacker. This represents an authorization bypass vulnerability where the whiteboard clone operation does not properly validate access permissions on linked issues. The attack requires network access to YouTrack and the ability to clone a whiteboard, but does not require authentication or special privileges beyond basic user access. An attacker can alter issue references, potentially disrupting project workflows or exposing confidential issue relationships.

Affected products

  • JetBrains YouTrack before 2026.2.18634

Timeline

  • 2026-09-07: disclosed

References

Related threats