CVE-2026-86492
- EPSS 0.56%
- Veröffentlicht 07.09.2026 17:17:27
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
CVE-2026-86493
- EPSS 0.17%
- Veröffentlicht 07.09.2026 17:17:27
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards
CVE-2026-86494
- EPSS 0.17%
- Veröffentlicht 07.09.2026 17:17:27
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
CVE-2026-86495
- EPSS 0.17%
- Veröffentlicht 07.09.2026 17:17:27
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects
CVE-2026-86496
- EPSS 0.16%
- Veröffentlicht 07.09.2026 17:17:27
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses
CVE-2026-86479
- EPSS 0.2%
- Veröffentlicht 07.09.2026 17:17:26
- Zuletzt bearbeitet 09.09.2026 05:18:19
In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
CVE-2026-86481
- EPSS 0.2%
- Veröffentlicht 07.09.2026 17:17:26
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
CVE-2026-86482
- EPSS 0.23%
- Veröffentlicht 07.09.2026 17:17:26
- Zuletzt bearbeitet 22.09.2026 10:17:09
In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation
CVE-2026-86483
- EPSS 0.38%
- Veröffentlicht 07.09.2026 17:17:26
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
CVE-2026-86484
- EPSS 0.38%
- Veröffentlicht 07.09.2026 17:17:26
- Zuletzt bearbeitet 08.09.2026 15:30:03
In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS