Junglewise Threat Intelligence

CVE-2026-86500: JetBrains YouTrack privilege escalation in project permissions

CVE-2026-86500 · Severity: medium · CVSS 5.5 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

YouTrack is a web-based issue tracking and project management system used by development teams. A flaw in permission checks allows users with basic project update permissions to escalate their own access to Project Administrator level without proper authorization, potentially giving them control over project settings, user access, and data.

Technical details

YouTrack contains an authorization bypass vulnerability where a missing escalation check in the permission model allows privilege escalation. A user authenticated with project update permissions can exploit this flaw to grant themselves Project Administrator role. The vulnerability requires the attacker to already hold update permissions on a project, but does not require additional user interaction. The flaw was patched in version 2026.1.14047 and later.

Affected products

  • JetBrains YouTrack before 2026.1.14047

Timeline

  • 2026-09-07: disclosed
  • 2026-01: patched: Fixed in version 2026.1.14047

References

Related threats