SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86492

HIGH · CVSS 8.5 EPSS 0.56%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in JetBrains YouTrack prior to version 2026.2.18634 allows for cross-tenant theft of GitHub App installation tokens due to a shared token cache. This could lead to unauthorized access to sensitive resources across different tenants, posing a significant risk to organizations using YouTrack for project management. GitHub App developers and organizations utilizing YouTrack should prioritize patching to mitigate potential security breaches.

CVE
CVE-2026-86492
Severity
HIGH
CVSS
8.5
EPSS
0.56%
GitHub

Original NVD Description

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens