Impact
The CVE-2026-86494 flaw in JetBrains YouTrack is a missing authorization issue that permits a user to clone a whiteboard and then perform unauthorized changes to links on issues that the user should not have access to. The only impact documented is that an attacker can alter the links associated with inaccessible issues, undermining the integrity of issue relationships. No evidence indicates that arbitrary URLs can be injected or issue workflows redirected.
Affected Systems
JetBrains YouTrack is affected. Any installation running a version before 2026.2.18634 is vulnerable to this flaw. Upgrading to 2026.2.18634 or a later release eliminates the issue.
Risk and Exploitability
With a CVSS score of 7.7 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that there is no confirmed widespread exploitation yet. The likely attack vector is through the web interface, where an authenticated user can clone a whiteboard and then manipulate link data on otherwise inaccessible issues. Because the flaw does not require remote code execution or elevated privilege, the risk is primarily internal and depends on the user’s ability to clone whiteboards within the application.
OpenCVE Enrichment