Description
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
Published: 2026-09-07
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE-2026-86494 flaw in JetBrains YouTrack is a missing authorization issue that permits a user to clone a whiteboard and then perform unauthorized changes to links on issues that the user should not have access to. The only impact documented is that an attacker can alter the links associated with inaccessible issues, undermining the integrity of issue relationships. No evidence indicates that arbitrary URLs can be injected or issue workflows redirected.

Affected Systems

JetBrains YouTrack is affected. Any installation running a version before 2026.2.18634 is vulnerable to this flaw. Upgrading to 2026.2.18634 or a later release eliminates the issue.

Risk and Exploitability

With a CVSS score of 7.7 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating that there is no confirmed widespread exploitation yet. The likely attack vector is through the web interface, where an authenticated user can clone a whiteboard and then manipulate link data on otherwise inaccessible issues. Because the flaw does not require remote code execution or elevated privilege, the risk is primarily internal and depends on the user’s ability to clone whiteboards within the application.

Generated by OpenCVE AI on September 7, 2026 at 17:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains YouTrack to version 2026.2.18634 or newer.
  • Restrict user permissions to disallow whiteboard cloning or prevent modification of issue links if an upgrade cannot be performed immediately.
  • Audit link alterations and monitor for unauthorized changes after applying any remediation.

Generated by OpenCVE AI on September 7, 2026 at 17:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title YouTrack Whiteboard Clone Allows Unauthorized Issue Link Modification

Mon, 07 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Mon, 07 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-09-07T16:26:46.753Z

Reserved: 2026-09-07T16:13:38.206Z

Link: CVE-2026-86494

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T17:17:27.753

Modified: 2026-09-07T17:17:27.753

Link: CVE-2026-86494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T18:00:10Z

Weaknesses