Technology · Jetbrains
Jetbrains YouTrack vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 43 vulnerabilities in Jetbrains YouTrack: 0 in the last 7 days and 32 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86500, was published on 7 September 2026.
- Last 7 days
- 0
- Last 90 days
- 32
- Critical, all time
- 2
- Exploited in the wild
- 0
About Jetbrains YouTrack
YouTrack is a browser-based project management tool and issue tracker.
Latest Jetbrains YouTrack vulnerabilities
- CVE-2026-86500: JetBrains YouTrack privilege escalation in project permissionsmediumCVSS 5.5EPSS 0.3%
- CVE-2026-86499: JetBrains YouTrack information disclosure in predefined search fieldsmediumCVSS 4.3EPSS 0.3%
- CVE-2026-86498: JetBrains YouTrack authorization bypass in link resourceshighCVSS 7.7EPSS 0.3%
- CVE-2026-86497: JetBrains YouTrack mailbox credential exfiltrationmediumCVSS 6.8EPSS 0.5%
- CVE-2026-86496: JetBrains YouTrack missing access control on Helpdesk authorized reportersmediumCVSS 4.3EPSS 0.3%
- CVE-2026-86495: JetBrains YouTrack missing permission checks in knowledge basemediumCVSS 6.5EPSS 0.3%
- CVE-2026-86494: JetBrains YouTrack unauthorized link modification via whiteboard clonehighCVSS 7.7EPSS 0.3%
- CVE-2026-86493: JetBrains YouTrack privilege escalation in whiteboard cardsmediumCVSS 6.5EPSS 0.3%
- CVE-2026-86492: JetBrains YouTrack cross-tenant GitHub App token thefthighCVSS 8.5EPSS 0.9%
- CVE-2026-86491: JetBrains YouTrack stored XSS in icon uploadslowCVSS 3.5EPSS 0.2%
- CVE-2026-86490: JetBrains YouTrack improper permission checks in app importmediumCVSS 6.5EPSS 0.3%
- CVE-2026-86489: JetBrains YouTrack IDOR in user profile APImediumCVSS 6.5EPSS 0.3%
- CVE-2026-86488: JetBrains YouTrack insecure direct object reference in watchRules and issueListConfigmediumCVSS 6.5EPSS 0.3%
- CVE-2026-86487: JetBrains YouTrack WebSocket privilege escalation in whiteboardlowCVSS 3.1EPSS 0.2%
- CVE-2026-86486: JetBrains YouTrack VCS webhook authentication bypasslowCVSS 3.7EPSS 0.3%
- CVE-2026-86485: JetBrains YouTrack IP spoofing via HTTP headers in Bitbucket webhook validationlowCVSS 3.3EPSS 0.2%
- CVE-2026-86484: JetBrains YouTrack stored XSS in assignee names via AngularJS template injectionmediumCVSS 4.6EPSS 0.6%
- CVE-2026-86483: JetBrains YouTrack stored XSS in custom field on Agile boardmediumCVSS 5.4EPSS 0.6%
- CVE-2026-86482: JetBrains YouTrack privilege escalation in role assignment validationhighCVSS 8.8EPSS 0.4%
- CVE-2026-86481: JetBrains YouTrack signed URL reuse in project icon disclosuremediumCVSS 4.3EPSS 0.3%
- CVE-2026-86479: JetBrains YouTrack missing authorization in REST APIhighCVSS 8.1EPSS 0.4%
- CVE-2026-75051: JetBrains YouTrack unauthorised project transfer between organisationshighCVSS 8.1EPSS 0.4%
- CVE-2026-75050: JetBrains YouTrack DoS attack via crafted type parametershighCVSS 7.1EPSS 1.1%
- CVE-2026-75049: JetBrains YouTrack unauthorized article access via draft endpointmediumCVSS 6.5EPSS 0.3%
- CVE-2026-75048: JetBrains YouTrack stored XSS in fenced code-block language labelhighCVSS 8.2EPSS 0.3%
Most severe Jetbrains YouTrack vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-62422: JetBrains YouTrack authentication bypass via direct database accesscriticalCVSS 10
- CVE-2026-75045: JetBrains YouTrack unauthenticated database backup downloadcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-86482: JetBrains YouTrack privilege escalation in role assignment validationhighCVSS 8.8EPSS 0.4%
- CVE-2026-49368: JetBrains YouTrack stored XSS in project notification templateshighCVSS 8.7
- CVE-2026-86492: JetBrains YouTrack cross-tenant GitHub App token thefthighCVSS 8.5EPSS 0.9%
- CVE-2026-75048: JetBrains YouTrack stored XSS in fenced code-block language labelhighCVSS 8.2EPSS 0.3%
- CVE-2026-75044: JetBrains YouTrack missing authorization in mailbox endpointhighCVSS 8.1EPSS 0.4%
- CVE-2026-86479: JetBrains YouTrack missing authorization in REST APIhighCVSS 8.1EPSS 0.4%
- CVE-2026-75051: JetBrains YouTrack unauthorised project transfer between organisationshighCVSS 8.1EPSS 0.4%
- CVE-2026-86498: JetBrains YouTrack authorization bypass in link resourceshighCVSS 7.7EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 1 | 1 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 8 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 21 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/youtrack.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Jetbrains YouTrack vulnerabilities", https://junglewise.ai/threats/technologies/youtrack, 26 September 2026.