Junglewise Threat Intelligence

CVE-2026-86498: JetBrains YouTrack authorization bypass in link resources

CVE-2026-86498 · Severity: high · CVSS 7.7 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is an issue and project tracking system used by development teams to manage work items and dependencies. A flaw in the API allows attackers to modify linked entities (issues, projects, or related records) through PUT requests to link sub-resources, bypassing permission checks. This enables unauthorized changes to critical project data without the proper update privileges.

Technical details

A privilege escalation vulnerability exists in YouTrack's REST API where PUT requests to link sub-resources fail to properly validate update permissions on the linked entities being modified. The vulnerability affects YouTrack versions before 2025.3.160480 and 2026.1.14047. An attacker with network access to the API can craft malicious PUT requests to modify linked entities without possessing the required update permission. This allows unauthorized modification of issue relationships, project links, or other interconnected data. The issue is fixed in JetBrains YouTrack 2025.3.160480 and 2026.1.14047.

Affected products

  • JetBrains YouTrack before 2025.3.160480, 2026.1.14047

Timeline

  • 2026-09-07: disclosed

References

Related threats