Description
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint
Published: 2026-09-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper permission check in JetBrains YouTrack before 2026.2.18634 permits an attacker to overwrite bundled applications through the app import endpoint. This flaw can allow an adversary to replace legitimate bundled apps with malicious ones, potentially leading to unauthorized code execution or persistence on a compromised instance. The weakness is specifically a missing or flawed authorization check (CWE-863).

Affected Systems

The vulnerability affects JetBrains YouTrack installations running versions earlier than 2026.2.18634. Administrators must verify the exact build number for their deployment.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote, through the publicly accessible app import endpoint; an attacker would need authentication or privileged access to target the endpoint. Given the absence of a publicly known exploit, the exploitation likelihood is currently unknown, but the potential impact on confidentiality, integrity, and availability warrants prompt remediation.

Generated by OpenCVE AI on September 7, 2026 at 17:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains YouTrack to version 2026.2.18634 or later to receive the official fix.
  • Restrict permissions on the app import endpoint so that only trusted administrative accounts can use it.
  • If the import functionality is not required, disable or remove the app import endpoint from the deployment to eliminate the attack surface.

Generated by OpenCVE AI on September 7, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Improper permission checks allow overwriting of bundled apps via app import endpoint
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Mon, 07 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-09-07T16:26:45.420Z

Reserved: 2026-09-07T16:13:36.999Z

Link: CVE-2026-86490

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T17:17:27.280

Modified: 2026-09-07T17:17:27.280

Link: CVE-2026-86490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T17:30:06Z

Weaknesses