SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86490

MEDIUM · CVSS 6.5 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2026.2.18634 are vulnerable due to improper permission checks that permit unauthorized overwriting of bundled applications through the app import endpoint. This flaw could lead to potential application compromise or service disruption. Organizations using affected versions should prioritize remediation to safeguard their application integrity and maintain operational security.

CVE
CVE-2026-86490
Severity
MEDIUM
CVSS
6.5
EPSS
0.19%

Original NVD Description

In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint