{"schema_version":1,"title":"Jetbrains YouTrack vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 43 vulnerabilities in Jetbrains YouTrack: 0 in the last 7 days and 32 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86500, was published on 7 September 2026.","url":"https://junglewise.ai/threats/technologies/youtrack","json_url":"https://junglewise.ai/threats/technologies/youtrack.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/youtrack","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":10,"all_time":43,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":21,"last_90_days":32,"last_365_days":43},"latest":[{"cve":"CVE-2026-86500","cvss":5.5,"epss":0.0027,"slug":"cve-2026-86500-jetbrains-youtrack-privilege-escalation-in-project-permissions","title":"JetBrains YouTrack privilege escalation in project permissions","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:28.443+00:00","url":"https://junglewise.ai/threats/cve-2026-86500-jetbrains-youtrack-privilege-escalation-in-project-permissions"},{"cve":"CVE-2026-86499","cvss":4.3,"epss":0.0027,"slug":"cve-2026-86499-jetbrains-youtrack-information-disclosure-in-predefined-search","title":"JetBrains YouTrack information disclosure in predefined search fields","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:28.33+00:00","url":"https://junglewise.ai/threats/cve-2026-86499-jetbrains-youtrack-information-disclosure-in-predefined-search"},{"cve":"CVE-2026-86498","cvss":7.7,"epss":0.003,"slug":"cve-2026-86498-jetbrains-youtrack-authorization-bypass-in-link-resources","title":"JetBrains YouTrack authorization bypass in link resources","severity":"high","exploited":false,"published_at":"2026-09-07T17:17:28.22+00:00","url":"https://junglewise.ai/threats/cve-2026-86498-jetbrains-youtrack-authorization-bypass-in-link-resources"},{"cve":"CVE-2026-86497","cvss":6.8,"epss":0.0051,"slug":"cve-2026-86497-jetbrains-youtrack-mailbox-credential-exfiltration","title":"JetBrains YouTrack mailbox credential exfiltration","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:28.097+00:00","url":"https://junglewise.ai/threats/cve-2026-86497-jetbrains-youtrack-mailbox-credential-exfiltration"},{"cve":"CVE-2026-86496","cvss":4.3,"epss":0.0028,"slug":"cve-2026-86496-jetbrains-youtrack-missing-access-control-on-helpdesk-authorized","title":"JetBrains YouTrack missing access control on Helpdesk authorized reporters","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:27.987+00:00","url":"https://junglewise.ai/threats/cve-2026-86496-jetbrains-youtrack-missing-access-control-on-helpdesk-authorized"},{"cve":"CVE-2026-86495","cvss":6.5,"epss":0.0033,"slug":"cve-2026-86495-jetbrains-youtrack-missing-permission-checks-in-knowledge-base","title":"JetBrains YouTrack missing permission checks in knowledge base","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:27.867+00:00","url":"https://junglewise.ai/threats/cve-2026-86495-jetbrains-youtrack-missing-permission-checks-in-knowledge-base"},{"cve":"CVE-2026-86494","cvss":7.7,"epss":0.003,"slug":"cve-2026-86494-jetbrains-youtrack-unauthorized-link-modification-via-whiteboard","title":"JetBrains YouTrack unauthorized link modification via whiteboard clone","severity":"high","exploited":false,"published_at":"2026-09-07T17:17:27.753+00:00","url":"https://junglewise.ai/threats/cve-2026-86494-jetbrains-youtrack-unauthorized-link-modification-via-whiteboard"},{"cve":"CVE-2026-86493","cvss":6.5,"epss":0.003,"slug":"cve-2026-86493-jetbrains-youtrack-privilege-escalation-in-whiteboard-cards","title":"JetBrains YouTrack privilege escalation in whiteboard cards","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:27.627+00:00","url":"https://junglewise.ai/threats/cve-2026-86493-jetbrains-youtrack-privilege-escalation-in-whiteboard-cards"},{"cve":"CVE-2026-86492","cvss":8.5,"epss":0.009,"slug":"cve-2026-86492-jetbrains-youtrack-cross-tenant-github-app-token-theft","title":"JetBrains YouTrack cross-tenant GitHub App token theft","severity":"high","exploited":false,"published_at":"2026-09-07T17:17:27.517+00:00","url":"https://junglewise.ai/threats/cve-2026-86492-jetbrains-youtrack-cross-tenant-github-app-token-theft"},{"cve":"CVE-2026-86491","cvss":3.5,"epss":0.0024,"slug":"cve-2026-86491-jetbrains-youtrack-stored-xss-in-icon-uploads","title":"JetBrains YouTrack stored XSS in icon uploads","severity":"low","exploited":false,"published_at":"2026-09-07T17:17:27.397+00:00","url":"https://junglewise.ai/threats/cve-2026-86491-jetbrains-youtrack-stored-xss-in-icon-uploads"},{"cve":"CVE-2026-86490","cvss":6.5,"epss":0.0033,"slug":"cve-2026-86490-jetbrains-youtrack-improper-permission-checks-in-app-import","title":"JetBrains YouTrack improper permission checks in app import","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:27.28+00:00","url":"https://junglewise.ai/threats/cve-2026-86490-jetbrains-youtrack-improper-permission-checks-in-app-import"},{"cve":"CVE-2026-86489","cvss":6.5,"epss":0.0034,"slug":"cve-2026-86489-jetbrains-youtrack-idor-in-user-profile-api","title":"JetBrains YouTrack IDOR in user profile API","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:27.167+00:00","url":"https://junglewise.ai/threats/cve-2026-86489-jetbrains-youtrack-idor-in-user-profile-api"},{"cve":"CVE-2026-86488","cvss":6.5,"epss":0.0034,"slug":"cve-2026-86488-jetbrains-youtrack-insecure-direct-object-reference-in-watchrules","title":"JetBrains YouTrack insecure direct object reference in watchRules and issueListConfig","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:27.053+00:00","url":"https://junglewise.ai/threats/cve-2026-86488-jetbrains-youtrack-insecure-direct-object-reference-in-watchrules"},{"cve":"CVE-2026-86487","cvss":3.1,"epss":0.002,"slug":"cve-2026-86487-jetbrains-youtrack-websocket-privilege-escalation-in-whiteboard","title":"JetBrains YouTrack WebSocket privilege escalation in whiteboard","severity":"low","exploited":false,"published_at":"2026-09-07T17:17:26.947+00:00","url":"https://junglewise.ai/threats/cve-2026-86487-jetbrains-youtrack-websocket-privilege-escalation-in-whiteboard"},{"cve":"CVE-2026-86486","cvss":3.7,"epss":0.0026,"slug":"cve-2026-86486-jetbrains-youtrack-vcs-webhook-authentication-bypass","title":"JetBrains YouTrack VCS webhook authentication bypass","severity":"low","exploited":false,"published_at":"2026-09-07T17:17:26.83+00:00","url":"https://junglewise.ai/threats/cve-2026-86486-jetbrains-youtrack-vcs-webhook-authentication-bypass"},{"cve":"CVE-2026-86485","cvss":3.3,"epss":0.0016,"slug":"cve-2026-86485-jetbrains-youtrack-ip-spoofing-via-http-headers-in-bitbucket","title":"JetBrains YouTrack IP spoofing via HTTP headers in Bitbucket webhook validation","severity":"low","exploited":false,"published_at":"2026-09-07T17:17:26.723+00:00","url":"https://junglewise.ai/threats/cve-2026-86485-jetbrains-youtrack-ip-spoofing-via-http-headers-in-bitbucket"},{"cve":"CVE-2026-86484","cvss":4.6,"epss":0.0064,"slug":"cve-2026-86484-jetbrains-youtrack-stored-xss-in-assignee-names-via-angularjs","title":"JetBrains YouTrack stored XSS in assignee names via AngularJS template injection","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:26.607+00:00","url":"https://junglewise.ai/threats/cve-2026-86484-jetbrains-youtrack-stored-xss-in-assignee-names-via-angularjs"},{"cve":"CVE-2026-86483","cvss":5.4,"epss":0.0064,"slug":"cve-2026-86483-jetbrains-youtrack-stored-xss-in-custom-field-on-agile-board","title":"JetBrains YouTrack stored XSS in custom field on Agile board","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:26.5+00:00","url":"https://junglewise.ai/threats/cve-2026-86483-jetbrains-youtrack-stored-xss-in-custom-field-on-agile-board"},{"cve":"CVE-2026-86482","cvss":8.8,"epss":0.0042,"slug":"cve-2026-86482-jetbrains-youtrack-privilege-escalation-in-role-assignment","title":"JetBrains YouTrack privilege escalation in role assignment validation","severity":"high","exploited":false,"published_at":"2026-09-07T17:17:26.383+00:00","url":"https://junglewise.ai/threats/cve-2026-86482-jetbrains-youtrack-privilege-escalation-in-role-assignment"},{"cve":"CVE-2026-86481","cvss":4.3,"epss":0.0027,"slug":"cve-2026-86481-jetbrains-youtrack-signed-url-reuse-in-project-icon-disclosure","title":"JetBrains YouTrack signed URL reuse in project icon disclosure","severity":"medium","exploited":false,"published_at":"2026-09-07T17:17:26.27+00:00","url":"https://junglewise.ai/threats/cve-2026-86481-jetbrains-youtrack-signed-url-reuse-in-project-icon-disclosure"},{"cve":"CVE-2026-86479","cvss":8.1,"epss":0.0035,"slug":"cve-2026-86479-jetbrains-youtrack-missing-authorization-in-rest-api","title":"JetBrains YouTrack missing authorization in REST API","severity":"high","exploited":false,"published_at":"2026-09-07T17:17:26.04+00:00","url":"https://junglewise.ai/threats/cve-2026-86479-jetbrains-youtrack-missing-authorization-in-rest-api"},{"cve":"CVE-2026-75051","cvss":8.1,"epss":0.0035,"slug":"cve-2026-75051-jetbrains-youtrack-unauthorised-project-transfer-between","title":"JetBrains YouTrack unauthorised project transfer between organisations","severity":"high","exploited":false,"published_at":"2026-08-17T16:17:52.213+00:00","url":"https://junglewise.ai/threats/cve-2026-75051-jetbrains-youtrack-unauthorised-project-transfer-between"},{"cve":"CVE-2026-75050","cvss":7.1,"epss":0.0106,"slug":"cve-2026-75050-jetbrains-youtrack-dos-attack-via-crafted-type-parameters","title":"JetBrains YouTrack DoS attack via crafted type parameters","severity":"high","exploited":false,"published_at":"2026-08-17T16:17:52.097+00:00","url":"https://junglewise.ai/threats/cve-2026-75050-jetbrains-youtrack-dos-attack-via-crafted-type-parameters"},{"cve":"CVE-2026-75049","cvss":6.5,"epss":0.0034,"slug":"cve-2026-75049-jetbrains-youtrack-unauthorized-article-access-via-draft-endpoint","title":"JetBrains YouTrack unauthorized article access via draft endpoint","severity":"medium","exploited":false,"published_at":"2026-08-17T16:17:51.987+00:00","url":"https://junglewise.ai/threats/cve-2026-75049-jetbrains-youtrack-unauthorized-article-access-via-draft-endpoint"},{"cve":"CVE-2026-75048","cvss":8.2,"epss":0.0032,"slug":"cve-2026-75048-jetbrains-youtrack-stored-xss-in-fenced-code-block-language-label","title":"JetBrains YouTrack stored XSS in fenced code-block language label","severity":"high","exploited":false,"published_at":"2026-08-17T16:17:51.87+00:00","url":"https://junglewise.ai/threats/cve-2026-75048-jetbrains-youtrack-stored-xss-in-fenced-code-block-language-label"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":1,"exploited":0,"vulnerabilities":8},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":21},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Jetbrains IntelliJ IDEA","slug":"intellij-idea","vulnerabilities":23,"url":"https://junglewise.ai/threats/technologies/intellij-idea"},{"name":"Jetbrains TeamCity","slug":"teamcity","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/teamcity"},{"name":"Jetbrains GoLand","slug":"goland","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/goland"},{"name":"Jetbrains Hub","slug":"hub","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/hub"},{"name":"Jetbrains PyCharm","slug":"pycharm","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/pycharm"},{"name":"Jetbrains Webstorm","slug":"webstorm","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/webstorm"}],"technology":{"hub":true,"name":"Jetbrains YouTrack","slug":"youtrack","vendor":{"name":"Jetbrains","slug":"jetbrains","url":"https://junglewise.ai/threats/vendors/jetbrains"},"aliases":[],"category":"project-management-software","homepage":"https://www.jetbrains.com/youtrack/","repo_url":"https://github.com/JetBrains/youtrack-issues","description":"YouTrack is a browser-based project management tool and issue tracker.","url":"https://junglewise.ai/threats/technologies/youtrack"},"most_severe":[{"cve":"CVE-2026-62422","cvss":10,"slug":"cve-2026-62422-jetbrains-youtrack-authentication-bypass-via-direct-database","title":"JetBrains YouTrack authentication bypass via direct database access","severity":"critical","exploited":false,"published_at":"2026-07-14T11:16:48.367+00:00","url":"https://junglewise.ai/threats/cve-2026-62422-jetbrains-youtrack-authentication-bypass-via-direct-database"},{"cve":"CVE-2026-75045","cvss":9.1,"epss":0.0042,"slug":"cve-2026-75045-jetbrains-youtrack-unauthenticated-database-backup-download","title":"JetBrains YouTrack unauthenticated database backup download","severity":"critical","exploited":false,"published_at":"2026-08-17T16:17:51.53+00:00","url":"https://junglewise.ai/threats/cve-2026-75045-jetbrains-youtrack-unauthenticated-database-backup-download"},{"cve":"CVE-2026-86482","cvss":8.8,"epss":0.0042,"slug":"cve-2026-86482-jetbrains-youtrack-privilege-escalation-in-role-assignment","title":"JetBrains YouTrack privilege escalation in role assignment validation","severity":"high","exploited":false,"published_at":"2026-09-07T17:17:26.383+00:00","url":"https://junglewise.ai/threats/cve-2026-86482-jetbrains-youtrack-privilege-escalation-in-role-assignment"},{"cve":"CVE-2026-49368","cvss":8.7,"slug":"cve-2026-49368-jetbrains-youtrack-stored-xss-in-project-notification-templates","title":"JetBrains YouTrack stored XSS in project notification templates","severity":"high","exploited":false,"published_at":"2026-05-29T19:16:26.553+00:00","url":"https://junglewise.ai/threats/cve-2026-49368-jetbrains-youtrack-stored-xss-in-project-notification-templates"},{"cve":"CVE-2026-86492","cvss":8.5,"epss":0.009,"slug":"cve-2026-86492-jetbrains-youtrack-cross-tenant-github-app-token-theft","title":"JetBrains YouTrack cross-tenant GitHub App token theft","severity":"high","exploited":false,"published_at":"2026-09-07T17:17:27.517+00:00","url":"https://junglewise.ai/threats/cve-2026-86492-jetbrains-youtrack-cross-tenant-github-app-token-theft"},{"cve":"CVE-2026-75048","cvss":8.2,"epss":0.0032,"slug":"cve-2026-75048-jetbrains-youtrack-stored-xss-in-fenced-code-block-language-label","title":"JetBrains YouTrack stored XSS in fenced code-block language label","severity":"high","exploited":false,"published_at":"2026-08-17T16:17:51.87+00:00","url":"https://junglewise.ai/threats/cve-2026-75048-jetbrains-youtrack-stored-xss-in-fenced-code-block-language-label"},{"cve":"CVE-2026-75044","cvss":8.1,"epss":0.0038,"slug":"cve-2026-75044-jetbrains-youtrack-missing-authorization-in-mailbox-endpoint","title":"JetBrains YouTrack missing authorization in mailbox endpoint","severity":"high","exploited":false,"published_at":"2026-08-17T16:17:51.41+00:00","url":"https://junglewise.ai/threats/cve-2026-75044-jetbrains-youtrack-missing-authorization-in-mailbox-endpoint"},{"cve":"CVE-2026-86479","cvss":8.1,"epss":0.0035,"slug":"cve-2026-86479-jetbrains-youtrack-missing-authorization-in-rest-api","title":"JetBrains YouTrack missing authorization in REST API","severity":"high","exploited":false,"published_at":"2026-09-07T17:17:26.04+00:00","url":"https://junglewise.ai/threats/cve-2026-86479-jetbrains-youtrack-missing-authorization-in-rest-api"},{"cve":"CVE-2026-75051","cvss":8.1,"epss":0.0035,"slug":"cve-2026-75051-jetbrains-youtrack-unauthorised-project-transfer-between","title":"JetBrains YouTrack unauthorised project transfer between organisations","severity":"high","exploited":false,"published_at":"2026-08-17T16:17:52.213+00:00","url":"https://junglewise.ai/threats/cve-2026-75051-jetbrains-youtrack-unauthorised-project-transfer-between"},{"cve":"CVE-2026-86498","cvss":7.7,"epss":0.003,"slug":"cve-2026-86498-jetbrains-youtrack-authorization-bypass-in-link-resources","title":"JetBrains YouTrack authorization bypass in link resources","severity":"high","exploited":false,"published_at":"2026-09-07T17:17:28.22+00:00","url":"https://junglewise.ai/threats/cve-2026-86498-jetbrains-youtrack-authorization-bypass-in-link-resources"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}