Description
In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
Published: 2026-09-07
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains YouTrack versions prior to 2026.1.14047 contain a missing authorization flaw that causes predefined search fields to expose every group name in the system. The vulnerability does not modify or delete data; its primary impact is the disclosure of potentially sensitive group membership information which could be used by an attacker to map internal structures, facilitate social engineering, or plan further attacks. This flaw is identified as CWE-862, a missing authorization weakness.

Affected Systems

Users of JetBrains YouTrack installations running any version earlier than 2026.1.14047 are affected. The issue applies to all users who can view predefined search fields, regardless of their group visibility permissions. No additional product or vendor versions are listed.

Risk and Exploitability

The CVSS base score of 4.3 indicates moderate impact, and the EPSS score is unavailable, so the current likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation at this time. Based on the description, it is inferred that the likely attack vector is accessing the UI or API with authenticated access, which can trigger the information leak by querying predefined search fields.

Generated by OpenCVE AI on September 7, 2026 at 18:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest YouTrack update, version 2026.1.14047 or later, which addresses the authorization flaw that lets users leak group names.
  • If an immediate update is not possible, temporarily restrict or disable the use of predefined search fields or remove the visibility of group names from the UI until a patch can be deployed.
  • Coordinate with JetBrains support or check their security advisories for any additional guidance on mitigating the vulnerability until a vendor patch is applied.

Generated by OpenCVE AI on September 7, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Predefined Search Fields Leak Group Names in JetBrains YouTrack

Mon, 07 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Mon, 07 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-09-07T16:26:48.575Z

Reserved: 2026-09-07T16:13:39.838Z

Link: CVE-2026-86499

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T17:17:28.330

Modified: 2026-09-07T17:17:28.330

Link: CVE-2026-86499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T18:45:17Z

Weaknesses