Junglewise Threat Intelligence

CVE-2026-86499: JetBrains YouTrack information disclosure in predefined search fields

CVE-2026-86499 · Severity: medium · CVSS 4.3 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a project tracking and issue management system used by software development teams. A vulnerability in the predefined search fields feature allowed unauthorized disclosure of all group names to any user, even those without permission to view specific groups. This could allow a user to discover the existence and names of confidential group structures within an organization.

Technical details

An information disclosure vulnerability in JetBrains YouTrack before version 2026.1.14047 failed to properly enforce group visibility permissions when displaying predefined search field values. The vulnerable component (predefined search fields) exposed group names regardless of the requesting user's visibility permissions. The vulnerability is reachable by any authenticated user without additional preconditions. An attacker can enumerate and discover all group names in the system, which may reveal sensitive organizational structure. The issue has been patched in YouTrack 2026.1.14047 and later.

Affected products

  • JetBrains YouTrack before 2026.1.14047

Timeline

  • 2026-09-07: disclosed

References

Related threats