CVE-2026-86499: CWE-862 in JetBrains YouTrack
A vulnerability in JetBrains YouTrack before version 2026.1.14047 allows any user to see all group names via predefined search fields, bypassing visibility permissions. This issue is classified as CWE-862 (Missing Authorization).
AI Analysis
Technical Summary
CVE-2026-86499 is a missing authorization vulnerability in JetBrains YouTrack affecting versions prior to 2026.1.14047. The flaw allows any user, regardless of their permission level, to access all group names through predefined search fields. This exposure leaks information about group names that should be restricted based on visibility permissions. The vulnerability has a CVSS 3.1 base score of 4.3, indicating a medium severity level. There is no vendor advisory or patch information currently available, and the product is not a cloud service.
Potential Impact
The vulnerability leads to unauthorized disclosure of group names within YouTrack. While this does not directly impact confidentiality of sensitive data or system integrity, it may aid attackers in reconnaissance or social engineering by revealing internal group structures. There is no indication of impact on data integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict user access to YouTrack or limit usage of predefined search fields if possible to reduce exposure.
CVE-2026-86499: CWE-862 in JetBrains YouTrack
Description
A vulnerability in JetBrains YouTrack before version 2026.1.14047 allows any user to see all group names via predefined search fields, bypassing visibility permissions. This issue is classified as CWE-862 (Missing Authorization).
CVSS v3.1
Score 4.3medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-86499 is a missing authorization vulnerability in JetBrains YouTrack affecting versions prior to 2026.1.14047. The flaw allows any user, regardless of their permission level, to access all group names through predefined search fields. This exposure leaks information about group names that should be restricted based on visibility permissions. The vulnerability has a CVSS 3.1 base score of 4.3, indicating a medium severity level. There is no vendor advisory or patch information currently available, and the product is not a cloud service.
Potential Impact
The vulnerability leads to unauthorized disclosure of group names within YouTrack. While this does not directly impact confidentiality of sensitive data or system integrity, it may aid attackers in reconnaissance or social engineering by revealing internal group structures. There is no indication of impact on data integrity or availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict user access to YouTrack or limit usage of predefined search fields if possible to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- JetBrains
- Date Reserved
- 2026-09-07T16:13:39.838Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a9ee85bacd9273b49f0e444
Added to database: 09/07/2026, 16:37:47 UTC
Last enriched: 09/07/2026, 16:53:42 UTC
Last updated: 09/07/2026, 21:16:23 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.