SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86488

MEDIUM · CVSS 6.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2026.2.18634 are vulnerable to an insecure direct object reference (iDOR) that allows unauthorized access to private saved searches through the watchRules and issueListConfig endpoints. This could lead to the exposure of sensitive information, impacting user privacy and data integrity. Organizations using affected versions should prioritize patching to mitigate potential data leaks.

CVE
CVE-2026-86488
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%

Original NVD Description

In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches