CVE-2026-86498CWE-863

In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

High · published September 7, 2026

CVSS v3.1
7.7
EPSS
In the wild
Unconfirmed
What it is

In JetBrains YouTrack before 2025.3.160480,

2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission

The record
Technical detail
CVSS v3.1
7.7 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
Not scored
Weakness
CWE-863 · Incorrect Authorization
Published
2026-09-07T16:26Z
Timeline
  • 07 SEP 16:26Z
    In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
    cvelistv5