Known Vulnerabilities for Youtrack by Jetbrains
Listed below are 10 of the newest known vulnerabilities associated with "Youtrack" by "Jetbrains".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86500 json | In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themsel... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86499 json | In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibili... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86498 json | In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked enti... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86497 json | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator t... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86496 json | In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addr... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86495 json | In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible ... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86494 json | In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86493 json | In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard ... | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86492 json | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens | Not Provided | 2026-09-07 | 2026-09-08 |
| CVE-2026-86491 json | In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads | Not Provided | 2026-09-07 | 2026-09-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jetbrains | Youtrack | 7.0.29566 | |||
| Application | Jetbrains | Youtrack | 7.0.28958 | |||
| Application | Jetbrains | Youtrack | 7.0.28450 | |||
| Application | Jetbrains | Youtrack | 7.0.28110 | |||
| Application | Jetbrains | Youtrack | 7.0.27965 | |||
| Application | Jetbrains | Youtrack | 7.0.27777 | |||
| Application | Jetbrains | Youtrack | 7.0.27705 | |||
| Application | Jetbrains | Youtrack | 7.0.27676 | |||
| Application | Jetbrains | Youtrack | 7.0.26927 | |||
| Application | Jetbrains | Youtrack | 7.0.26754 | |||
| Application | Jetbrains | Youtrack | 7.0.26630 | |||
| Application | Jetbrains | Youtrack | 7.0.26198 | |||
| Application | Jetbrains | Youtrack | 6.5.17122 | |||
| Application | Jetbrains | Youtrack | 6.5.17105 | |||
| Application | Jetbrains | Youtrack | 6.5.17057 | |||
| Application | Jetbrains | Youtrack | 6.5.17031 | |||
| Application | Jetbrains | Youtrack | 6.0.12634 | |||
| Application | Jetbrains | Youtrack | 6.0.12124 | |||
| Application | Jetbrains | Youtrack | 5.2.5 | |||
| Application | Jetbrains | Youtrack | 4.2.4 |