CyberRota Analysis
AI-GeneratedA vulnerability in JetBrains YouTrack prior to version 2026.2.18634 allows for cross-tenant theft of GitHub App installation tokens due to a shared token cache. This could lead to unauthorized access to sensitive resources across different tenants, posing a significant risk to organizations using YouTrack for project management. GitHub App developers and organizations utilizing YouTrack should prioritize patching to mitigate potential security breaches.
CVE
CVE-2026-86492
Severity
HIGH
CVSS
8.5
EPSS
0.56%
GitHub
Original NVD Description
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens