CyberRota Analysis
AI-GeneratedJetBrains YouTrack versions prior to 2026.1.14047 have a vulnerability where predefined search fields expose all group names to any user, bypassing visibility permissions. This could lead to unauthorized information disclosure, potentially compromising sensitive group data within the application. Organizations using affected versions should prioritize remediation to protect user privacy and maintain data confidentiality.
CVE
CVE-2026-86499
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%
Original NVD Description
In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission