SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86500

MEDIUM · CVSS 5.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2026.1.14047 are vulnerable due to a missing escalation check, allowing users with project update permissions to elevate their access to Project Admin. This could lead to unauthorized changes and potential data exposure within projects. Organizations utilizing YouTrack should prioritize addressing this vulnerability to mitigate risks associated with unauthorized privilege escalation.

CVE
CVE-2026-86500
Severity
MEDIUM
CVSS
5.5
EPSS
0.16%

Original NVD Description

In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin