These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-86506 debrief based on CVE Program and NVD records. The vulnerability affects JetBrains GoLand before version 2026.2.2.1, exposing profiling data due to missing authentication on the profiler's injected pprof server. This MEDIUM-severity issue, with a CVSS score of 5.9, requires users and administrators to assess exposure and verify patching to prevent potential data exposure. The CVE record and [truncated]
A low-severity vulnerability was found in JetBrains IntelliJ IDEA before version 2026.2.2, where a missing project-trust check could leak project metadata to JetBrains Marketplace. This issue, with a CVSS score of 3.3, is caused by inadequate checks in the project trust settings, potentially exposing project information. Defenders should verify IntelliJ IDEA versions and assess project trust settings to p [truncated]
CVE-2026-86504 debrief based on the supplied source corpus. The vulnerability affects JetBrains IntelliJ IDEA versions before 2026.2.2, allowing host-level code execution due to missing project-trust confirmation before building a Dev Container. This issue has significant implications for defenders and security teams responsible for IntelliJ IDEA deployments. They should assess exposure and verify compens [truncated]
CVE-2026-86503 is a LOW-severity vulnerability in JetBrains IntelliJ IDEA that could lead to Server-Side Request Forgery (SSRF) attacks via Kubernetes spec-source URL fetching when opening an untrusted project. The vulnerability exists in versions before 2026.2.2. Defenders should prioritize verifying exposure, especially in deployments allowing untrusted projects, and consider updating to version 2026.2. [truncated]
CVE-2026-86502 debrief based on the supplied source corpus. The IJent gRPC server in JetBrains IntelliJ IDEA before 2026.2.2 lacks TLS and authentication, allowing local code execution on Remote Development hosts. This vulnerability affects Remote Development hosts and JetBrains IntelliJ IDEA installations, with potential for unauthorized access to sensitive data. Defenders should assess exposure and prio [truncated]
A low-severity vulnerability was found in JetBrains IntelliJ IDEA before version 2026.2.2, where terminal command input could be written to the idea.log file. This issue could potentially lead to the logging of sensitive information. Defenders and administrators should assess exposure and verify logging configurations to ensure that sensitive information is not being written to log files. The vulnerabilit [truncated]
A vulnerability in JetBrains YouTrack before 2026.1.14047 allows a user with project update permissions to grant themselves Project Admin privileges due to a missing escalation check. This issue is classified as CWE-266. The vulnerability requires verification of user permissions and prompt patch application to prevent potential privilege escalation attacks. Defenders and administrators of JetBrains YouTr [truncated]
CVE-2026-86499 is a medium-severity vulnerability in JetBrains YouTrack before version 2026.1.14047. The issue allows predefined search fields to leak all group names to any user, regardless of their visibility permissions. This vulnerability could potentially expose sensitive group names and permissions, leading to unauthorized access to sensitive information. Defenders and administrators of JetBrains Yo [truncated]
CVE-2026-86498 is a high-severity vulnerability in JetBrains YouTrack, allowing modification of linked entities without update permission via PUT requests on link sub-resources. This issue was reported in versions before 2025.3.160480 and 2026.1.14047. The vulnerability impacts systems where unauthorized modifications could occur, emphasizing the need for defenders and administrators to assess exposure an [truncated]
A vulnerability in JetBrains YouTrack before 2026.2.18769 allows project administrators to exfiltrate stored mailbox credentials by changing the mailbox host without re-authentication. This issue arises because the software does not require re-authentication when altering mailbox host settings, potentially leading to unauthorized access. Defenders should verify that their YouTrack installations are update [truncated]
CVE-2026-86496 debrief: JetBrains YouTrack before 2026.2.18769 exposed reporter email addresses due to missing access control on Helpdesk authorized reporters. This vulnerability, classified as MEDIUM severity with a CVSS score of 4.3, impacts defenders responsible for JetBrains YouTrack deployments, especially those using versions prior to 2026.2.18769. The issue allows for potential information disclosu [truncated]
CVE-2026-86495 debrief based on CVE Program and NVD records. The vulnerability allows users to create knowledge base articles in inaccessible projects due to missing permission checks in JetBrains YouTrack before 2026.2.18687. This medium-severity issue may lead to information disclosure or unauthorized changes. Defenders should verify YouTrack instances for unauthorized knowledge base article creation an [truncated]
CVE-2026-86494 debrief based on CVE Program and NVD records. The vulnerability allows unauthorized changes to links on inaccessible issues when cloning a whiteboard in JetBrains YouTrack, impacting issue tracking and project management. Administrators and users should assess exposure and verify inventory. The vulnerability requires verification of affected versions and remediation efforts, with a HIGH sev [truncated]
CVE-2026-86493 debrief based on CVE Program and NVD records. The vulnerability affects JetBrains YouTrack before version 2026.2.18634, allowing read-only users to create and modify whiteboard cards due to improper permission checks. This issue has a CVSS score of 6.5 and is classified as MEDIUM severity. Defenders and administrators of JetBrains YouTrack instances should assess exposure and verify remedia [truncated]
CVE-2026-86492 debrief based on the supplied source corpus. The vulnerability is a high-severity issue in JetBrains YouTrack before 2026.2.18634, allowing cross-tenant theft of GitHub App installation tokens due to a shared token cache issue. This could lead to potential token theft and cross-tenant access risks in shared YouTrack environments. Defenders responsible for YouTrack deployments, especially th [truncated]
CVE-2026-86491 describes a stored XSS vulnerability in JetBrains YouTrack before version 2026.2.18634. The vulnerability could be exploited via project and organization icon uploads, potentially leading to XSS attacks on users of affected YouTrack instances. Defenders responsible for JetBrains YouTrack deployments should assess exposure and prioritize patching or upgrading to version 2026.2.18634 or later [truncated]
CVE-2026-86490 is a medium-severity vulnerability in JetBrains YouTrack before version 2026.2.18634. The issue allows improper permission checks, enabling overwriting of bundled apps via the app import endpoint. This CVE was published on 2026-09-07T17:17:27.280Z and has not been modified since then. Affected product deployments should be identified in managed environments, and owners should be assigned fo [truncated]
CVE-2026-86489 is a medium-severity IDOR vulnerability in JetBrains YouTrack before version 2026.2.18634. The vulnerability allows for the disclosure of private issues and starred folders across organizations. Defenders responsible for YouTrack instances should assess exposure and prioritize verification and remediation efforts. The CVE record and NVD entry provide limited information about the vulnerabil [truncated]
CVE-2026-86488 debrief based on the supplied source corpus. The CVE record was published on 2026-09-07T17:17:27.053Z and has not been modified since then. This medium-severity vulnerability in JetBrains YouTrack exposes private saved searches through watchRules and issueListConfig endpoints, potentially allowing unauthorized access to sensitive information. Defenders should assess their exposure, especial [truncated]
CVE-2026-86487 debrief based on CVE Program and NVD records. A crafted WebSocket message allowed read-only whiteboard users to modify canvas content in JetBrains YouTrack before 2026.2.18634. This vulnerability has a CVSS score of 3.1, indicating low severity. Defenders responsible for JetBrains YouTrack instances should assess exposure and verify canvas content modification by read-only whiteboard users. [truncated]
A low-severity vulnerability was found in JetBrains YouTrack before version 2026.2.18634. The generic VCS webhook handler fails to open when its secret is blank. This issue has a CVSS score of 3.7 and is classified as a low-severity vulnerability. Defenders responsible for YouTrack installations should verify and update their systems to prevent potential issues. The CVE record and NVD entry provide limite [truncated]
A low-severity vulnerability was found in JetBrains YouTrack before version 2026.2.18634, allowing IP spoofing via HTTP headers, which could be used to forge Bitbucket webhooks. This issue, with a CVSS score of 3.3, poses a low risk but could impact organizations using YouTrack for issue tracking and project management, particularly those integrating with Bitbucket for version control. Defenders should as [truncated]
CVE-2026-86484 debrief based on the supplied source corpus. The vulnerability allows stored XSS via angularJS template injection in assignee names in JetBrains YouTrack before 2026.2.18634. Defenders should assess exposure, prioritize verification of user interactions, and update vulnerable deployments. The CVE record and NVD entry indicate a medium-severity vulnerability. An attacker with limited privile [truncated]
CVE-2026-86483 debrief based on the supplied source corpus. The vulnerability is a medium-severity stored XSS issue in JetBrains YouTrack before version 2026.2.18634, affecting Agile board cards with custom fields. Defenders should assess exposure, verify versions, and monitor for suspicious activity. The CVE record and NVD entry indicate that user interaction is required, and the vulnerability can result [truncated]
CVE-2026-86482 debrief based on CVE Program and NVD records. The vulnerability involves insufficient validation of role assignments in JetBrains YouTrack before version 2026.2.18634, allowing for privilege escalation. This issue has a CVSS score of 8.8 and is classified as HIGH. Defenders responsible for YouTrack deployments should assess exposure and verify role assignments to prevent unauthorized access [truncated]
CVE-2026-86481 is a medium-severity vulnerability in JetBrains YouTrack, allowing disclosure of restricted project icons due to signed URL reuse. This issue was patched in version 2026.2.18634. Defenders responsible for JetBrains YouTrack instances should assess exposure and prioritize remediation to prevent potential disclosure of sensitive information. The vulnerability's impact is limited to the disclo [truncated]
PatchSiren debrief for CVE-2026-86479, a high-severity vulnerability in JetBrains YouTrack. This vulnerability, identified as CVE-2026-86479, affects JetBrains YouTrack, potentially allowing access to restricted REST API resources via IDOR. The vulnerability has a CVSS score of 8.1 and is considered high severity. Defenders responsible for JetBrains YouTrack deployments should assess exposure and prioriti [truncated]
CVE-2026-86478 is a critical vulnerability in JetBrains YouTrack before 2025.3.161254 and 2026.1.14042, allowing unauthenticated account takeover via a self-asserted email address. This vulnerability impacts organizations using affected versions of JetBrains YouTrack, potentially allowing attackers to gain unauthorized access to user accounts. Defenders responsible for JetBrains YouTrack deployments shoul [truncated]
CVE-2026-75060 debrief based on the supplied source corpus. The vulnerability allows code execution via unauthenticated Jupyter MCP tools in JetBrains PyCharm before 2026.2.1. PyCharm users and administrators should assess exposure and take remediation steps. The CVE record and NVD entry provide details on the vulnerability, but additional verification is necessary to confirm affected scope and severity. [truncated]
CVE-2026-75059 debrief based on the supplied source corpus. The vulnerability allows code execution via Quick Documentation in JetBrains PyCharm before 2026.2.1, with a CVSS score of 4.4. PyCharm users and administrators should verify their version and upgrade to 2026.2.1 or later to mitigate the vulnerability. The CVE record and NVD entry provide details on the vulnerability, including its severity and p [truncated]