Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5601 articles · 220742 vulns · 37/41 feeds (7d)
← Back to list
8.0
CVE-2026-86479PATCHED
jetbrains · youtrack

CVE-2026-86479: In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restric

Description

In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR

Affected Products

VendorProductVersions
jetbrainsyoutrack0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
jetbrainsyou trackcert_advisory90%

References

  • https://www.jetbrains.com/privacy-security/issues-fixed/

Related News (2 articles)

Tier B
BSI Advisories14d ago
[NEU] [hoch] JetBrains You Track: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB14d ago
CVE-2026-86479 | JetBrains YouTrack prior 2026.2.18788/2026.1.14055/2025.3.161254 authorization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.0 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.2.187882026.1.140552025.3.161254
CWECWE-862
PublishedSep 7, 2026
Last enriched14d ago
Trending Score9
Source articles2
Independent2
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-63077EXPKEV
CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
Trending: 16
CRITICALCVE-2026-86478
CVE-2026-86478: In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthent
Trending: 12
CRITICALCVE-2026-86480
CVE-2026-86480: In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser pri
Trending: 9
HIGHCVE-2026-86482
CVE-2026-86482: In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation
Trending: 9
HIGHCVE-2026-86504
CVE-2026-86504: In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed ho
Trending: 9

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 7, 2026
Discovered by ZDM
Sep 7, 2026
Patch Available
Sep 9, 2026