CVE-2026-86495CWE-862

In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects

Medium · published September 7, 2026

CVSS v3.1
6.5
EPSS
In the wild
Unconfirmed
What it is

In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
Not scored
Weakness
CWE-862 · Missing Authorization
Published
2026-09-07T16:26Z
Timeline
  • 07 SEP 16:26Z
    In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects
    cvelistv5