SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86499

MEDIUM · CVSS 4.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2026.1.14047 have a vulnerability where predefined search fields expose all group names to any user, bypassing visibility permissions. This could lead to unauthorized information disclosure, potentially compromising sensitive group data within the application. Organizations using affected versions should prioritize remediation to protect user privacy and maintain data confidentiality.

CVE
CVE-2026-86499
Severity
MEDIUM
CVSS
4.3
EPSS
0.16%

Original NVD Description

In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission