SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86479

HIGH · CVSS 8.1 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2026.2.18788, 2026.1.14055, and 2025.3.161254 are vulnerable to an authorization bypass due to an Insecure Direct Object Reference (IDOR), allowing unauthorized access to restricted REST API resources. This vulnerability poses a high risk as it could lead to exposure of sensitive data or manipulation of project resources. Organizations using affected versions should prioritize remediation to safeguard their project management environments.

CVE
CVE-2026-86479
Severity
HIGH
CVSS
8.1
EPSS
0.20%

Original NVD Description

In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR