CVE-2026-86492
Received Received - Intake

Cross-Tenant GitHub App Token Theft in YouTrack

Vulnerability report for CVE-2026-86492, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: JetBrains s.r.o.

Description

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jetbrains youtrack to 2026.2.18634 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-488 The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JetBrains YouTrack before version 2026.2.18634 has a vulnerability where a shared token cache could allow an attacker to steal GitHub App installation tokens across different tenants. This means unauthorized users might gain access to tokens that belong to other accounts or organizations.

Impact Analysis

If you use JetBrains YouTrack with GitHub App integration, this vulnerability could allow attackers to access your GitHub repositories or data by stealing installation tokens. This may lead to unauthorized code changes, data leaks, or other malicious activities depending on the token's permissions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations using YouTrack may face compliance violations if tokens with access to regulated data are compromised.

Mitigation Strategies

Update JetBrains YouTrack to version 2026.2.18634 or later to address the shared token cache issue. Review and revoke any potentially exposed GitHub App installation tokens. Monitor for unauthorized access or unusual activity in your YouTrack instance.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86492. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart