SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86489

MEDIUM · CVSS 6.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An insecure direct object reference (IDOR) vulnerability in JetBrains YouTrack prior to version 2026.2.18634 allows unauthorized access to private issues and starred folders across different organizations through the user profile API. This could lead to the exposure of sensitive information, impacting user privacy and data security. Organizations using affected versions should prioritize remediation to protect their data integrity and user confidentiality.

CVE
CVE-2026-86489
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%

Original NVD Description

In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations