CyberRota Analysis
AI-GeneratedJetBrains YouTrack versions prior to 2026.1.14047 are vulnerable due to a missing escalation check, allowing users with project update permissions to elevate their access to Project Admin. This could lead to unauthorized changes and potential data exposure within projects. Organizations utilizing YouTrack should prioritize addressing this vulnerability to mitigate risks associated with unauthorized privilege escalation.
CVE
CVE-2026-86500
Severity
MEDIUM
CVSS
5.5
EPSS
0.16%
Original NVD Description
In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin