SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86498

HIGH · CVSS 7.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2025.3.160480 and 2026.1.14047 are vulnerable to unauthorized modifications of linked entities through pUT requests on sub-resources, bypassing necessary update permissions. This flaw could lead to unauthorized data manipulation, potentially compromising project integrity and user trust. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-86498
Severity
HIGH
CVSS
7.7
EPSS
0.17%

Original NVD Description

In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission