CVE-2026-86498 Details
Description
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
A vulnerability exists in JetBrains YouTrack versions prior to 2025.3.160480 and 2026.1.14047. The issue arises from PUT requests on link sub-resources, which improperly allow modifications to linked entities without the necessary update permissions. This flaw could be exploited to alter project data or workflows, potentially leading to unauthorized changes in issue management or project tracking.
Users can update to YouTrack versions 2025.3.161254, 2026.1.14042, or 2026.2.18788, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 7, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ | [email protected] | AdvisoryBundleVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| JetBrains YouTrack | >= 2025.3, < 2025.3.161254 >= 2026.1, < 2026.1.14042 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 7, 2026 | New CVE Received | [email protected] |
Volerion