PatchSiren

JetBrains CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86506

CVE-2026-86506 debrief based on CVE Program and NVD records. The vulnerability affects JetBrains GoLand before version 2026.2.2.1, exposing profiling data due to missing authentication on the profiler's injected pprof server. This MEDIUM-severity issue, with a CVSS score of 5.9, requires users and administrators to assess exposure and verify patching to prevent potential data exposure. The CVE record and [truncated]

LOW JetBrains CVE published 2026-09-07

CVE-2026-86505

A low-severity vulnerability was found in JetBrains IntelliJ IDEA before version 2026.2.2, where a missing project-trust check could leak project metadata to JetBrains Marketplace. This issue, with a CVSS score of 3.3, is caused by inadequate checks in the project trust settings, potentially exposing project information. Defenders should verify IntelliJ IDEA versions and assess project trust settings to p [truncated]

HIGH JetBrains CVE published 2026-09-07

CVE-2026-86504

CVE-2026-86504 debrief based on the supplied source corpus. The vulnerability affects JetBrains IntelliJ IDEA versions before 2026.2.2, allowing host-level code execution due to missing project-trust confirmation before building a Dev Container. This issue has significant implications for defenders and security teams responsible for IntelliJ IDEA deployments. They should assess exposure and verify compens [truncated]

LOW JetBrains CVE published 2026-09-07

CVE-2026-86503

CVE-2026-86503 is a LOW-severity vulnerability in JetBrains IntelliJ IDEA that could lead to Server-Side Request Forgery (SSRF) attacks via Kubernetes spec-source URL fetching when opening an untrusted project. The vulnerability exists in versions before 2026.2.2. Defenders should prioritize verifying exposure, especially in deployments allowing untrusted projects, and consider updating to version 2026.2. [truncated]

HIGH JetBrains CVE published 2026-09-07

CVE-2026-86502

CVE-2026-86502 debrief based on the supplied source corpus. The IJent gRPC server in JetBrains IntelliJ IDEA before 2026.2.2 lacks TLS and authentication, allowing local code execution on Remote Development hosts. This vulnerability affects Remote Development hosts and JetBrains IntelliJ IDEA installations, with potential for unauthorized access to sensitive data. Defenders should assess exposure and prio [truncated]

LOW JetBrains CVE published 2026-09-07

CVE-2026-86501

A low-severity vulnerability was found in JetBrains IntelliJ IDEA before version 2026.2.2, where terminal command input could be written to the idea.log file. This issue could potentially lead to the logging of sensitive information. Defenders and administrators should assess exposure and verify logging configurations to ensure that sensitive information is not being written to log files. The vulnerabilit [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86500

A vulnerability in JetBrains YouTrack before 2026.1.14047 allows a user with project update permissions to grant themselves Project Admin privileges due to a missing escalation check. This issue is classified as CWE-266. The vulnerability requires verification of user permissions and prompt patch application to prevent potential privilege escalation attacks. Defenders and administrators of JetBrains YouTr [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86499

CVE-2026-86499 is a medium-severity vulnerability in JetBrains YouTrack before version 2026.1.14047. The issue allows predefined search fields to leak all group names to any user, regardless of their visibility permissions. This vulnerability could potentially expose sensitive group names and permissions, leading to unauthorized access to sensitive information. Defenders and administrators of JetBrains Yo [truncated]

HIGH JetBrains CVE published 2026-09-07

CVE-2026-86498

CVE-2026-86498 is a high-severity vulnerability in JetBrains YouTrack, allowing modification of linked entities without update permission via PUT requests on link sub-resources. This issue was reported in versions before 2025.3.160480 and 2026.1.14047. The vulnerability impacts systems where unauthorized modifications could occur, emphasizing the need for defenders and administrators to assess exposure an [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86497

A vulnerability in JetBrains YouTrack before 2026.2.18769 allows project administrators to exfiltrate stored mailbox credentials by changing the mailbox host without re-authentication. This issue arises because the software does not require re-authentication when altering mailbox host settings, potentially leading to unauthorized access. Defenders should verify that their YouTrack installations are update [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86496

CVE-2026-86496 debrief: JetBrains YouTrack before 2026.2.18769 exposed reporter email addresses due to missing access control on Helpdesk authorized reporters. This vulnerability, classified as MEDIUM severity with a CVSS score of 4.3, impacts defenders responsible for JetBrains YouTrack deployments, especially those using versions prior to 2026.2.18769. The issue allows for potential information disclosu [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86495

CVE-2026-86495 debrief based on CVE Program and NVD records. The vulnerability allows users to create knowledge base articles in inaccessible projects due to missing permission checks in JetBrains YouTrack before 2026.2.18687. This medium-severity issue may lead to information disclosure or unauthorized changes. Defenders should verify YouTrack instances for unauthorized knowledge base article creation an [truncated]

HIGH JetBrains CVE published 2026-09-07

CVE-2026-86494

CVE-2026-86494 debrief based on CVE Program and NVD records. The vulnerability allows unauthorized changes to links on inaccessible issues when cloning a whiteboard in JetBrains YouTrack, impacting issue tracking and project management. Administrators and users should assess exposure and verify inventory. The vulnerability requires verification of affected versions and remediation efforts, with a HIGH sev [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86493

CVE-2026-86493 debrief based on CVE Program and NVD records. The vulnerability affects JetBrains YouTrack before version 2026.2.18634, allowing read-only users to create and modify whiteboard cards due to improper permission checks. This issue has a CVSS score of 6.5 and is classified as MEDIUM severity. Defenders and administrators of JetBrains YouTrack instances should assess exposure and verify remedia [truncated]

HIGH JetBrains CVE published 2026-09-07

CVE-2026-86492

CVE-2026-86492 debrief based on the supplied source corpus. The vulnerability is a high-severity issue in JetBrains YouTrack before 2026.2.18634, allowing cross-tenant theft of GitHub App installation tokens due to a shared token cache issue. This could lead to potential token theft and cross-tenant access risks in shared YouTrack environments. Defenders responsible for YouTrack deployments, especially th [truncated]

LOW JetBrains CVE published 2026-09-07

CVE-2026-86491

CVE-2026-86491 describes a stored XSS vulnerability in JetBrains YouTrack before version 2026.2.18634. The vulnerability could be exploited via project and organization icon uploads, potentially leading to XSS attacks on users of affected YouTrack instances. Defenders responsible for JetBrains YouTrack deployments should assess exposure and prioritize patching or upgrading to version 2026.2.18634 or later [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86490

CVE-2026-86490 is a medium-severity vulnerability in JetBrains YouTrack before version 2026.2.18634. The issue allows improper permission checks, enabling overwriting of bundled apps via the app import endpoint. This CVE was published on 2026-09-07T17:17:27.280Z and has not been modified since then. Affected product deployments should be identified in managed environments, and owners should be assigned fo [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86489

CVE-2026-86489 is a medium-severity IDOR vulnerability in JetBrains YouTrack before version 2026.2.18634. The vulnerability allows for the disclosure of private issues and starred folders across organizations. Defenders responsible for YouTrack instances should assess exposure and prioritize verification and remediation efforts. The CVE record and NVD entry provide limited information about the vulnerabil [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86488

CVE-2026-86488 debrief based on the supplied source corpus. The CVE record was published on 2026-09-07T17:17:27.053Z and has not been modified since then. This medium-severity vulnerability in JetBrains YouTrack exposes private saved searches through watchRules and issueListConfig endpoints, potentially allowing unauthorized access to sensitive information. Defenders should assess their exposure, especial [truncated]

LOW JetBrains CVE published 2026-09-07

CVE-2026-86487

CVE-2026-86487 debrief based on CVE Program and NVD records. A crafted WebSocket message allowed read-only whiteboard users to modify canvas content in JetBrains YouTrack before 2026.2.18634. This vulnerability has a CVSS score of 3.1, indicating low severity. Defenders responsible for JetBrains YouTrack instances should assess exposure and verify canvas content modification by read-only whiteboard users. [truncated]

LOW JetBrains CVE published 2026-09-07

CVE-2026-86486

A low-severity vulnerability was found in JetBrains YouTrack before version 2026.2.18634. The generic VCS webhook handler fails to open when its secret is blank. This issue has a CVSS score of 3.7 and is classified as a low-severity vulnerability. Defenders responsible for YouTrack installations should verify and update their systems to prevent potential issues. The CVE record and NVD entry provide limite [truncated]

LOW JetBrains CVE published 2026-09-07

CVE-2026-86485

A low-severity vulnerability was found in JetBrains YouTrack before version 2026.2.18634, allowing IP spoofing via HTTP headers, which could be used to forge Bitbucket webhooks. This issue, with a CVSS score of 3.3, poses a low risk but could impact organizations using YouTrack for issue tracking and project management, particularly those integrating with Bitbucket for version control. Defenders should as [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86484

CVE-2026-86484 debrief based on the supplied source corpus. The vulnerability allows stored XSS via angularJS template injection in assignee names in JetBrains YouTrack before 2026.2.18634. Defenders should assess exposure, prioritize verification of user interactions, and update vulnerable deployments. The CVE record and NVD entry indicate a medium-severity vulnerability. An attacker with limited privile [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86483

CVE-2026-86483 debrief based on the supplied source corpus. The vulnerability is a medium-severity stored XSS issue in JetBrains YouTrack before version 2026.2.18634, affecting Agile board cards with custom fields. Defenders should assess exposure, verify versions, and monitor for suspicious activity. The CVE record and NVD entry indicate that user interaction is required, and the vulnerability can result [truncated]

HIGH JetBrains CVE published 2026-09-07

CVE-2026-86482

CVE-2026-86482 debrief based on CVE Program and NVD records. The vulnerability involves insufficient validation of role assignments in JetBrains YouTrack before version 2026.2.18634, allowing for privilege escalation. This issue has a CVSS score of 8.8 and is classified as HIGH. Defenders responsible for YouTrack deployments should assess exposure and verify role assignments to prevent unauthorized access [truncated]

MEDIUM JetBrains CVE published 2026-09-07

CVE-2026-86481

CVE-2026-86481 is a medium-severity vulnerability in JetBrains YouTrack, allowing disclosure of restricted project icons due to signed URL reuse. This issue was patched in version 2026.2.18634. Defenders responsible for JetBrains YouTrack instances should assess exposure and prioritize remediation to prevent potential disclosure of sensitive information. The vulnerability's impact is limited to the disclo [truncated]

HIGH JetBrains CVE published 2026-09-07

CVE-2026-86479

PatchSiren debrief for CVE-2026-86479, a high-severity vulnerability in JetBrains YouTrack. This vulnerability, identified as CVE-2026-86479, affects JetBrains YouTrack, potentially allowing access to restricted REST API resources via IDOR. The vulnerability has a CVSS score of 8.1 and is considered high severity. Defenders responsible for JetBrains YouTrack deployments should assess exposure and prioriti [truncated]

CRITICAL JetBrains CVE published 2026-09-07

CVE-2026-86478

CVE-2026-86478 is a critical vulnerability in JetBrains YouTrack before 2025.3.161254 and 2026.1.14042, allowing unauthenticated account takeover via a self-asserted email address. This vulnerability impacts organizations using affected versions of JetBrains YouTrack, potentially allowing attackers to gain unauthorized access to user accounts. Defenders responsible for JetBrains YouTrack deployments shoul [truncated]

HIGH JetBrains CVE published 2026-08-17

CVE-2026-75060

CVE-2026-75060 debrief based on the supplied source corpus. The vulnerability allows code execution via unauthenticated Jupyter MCP tools in JetBrains PyCharm before 2026.2.1. PyCharm users and administrators should assess exposure and take remediation steps. The CVE record and NVD entry provide details on the vulnerability, but additional verification is necessary to confirm affected scope and severity. [truncated]

MEDIUM JetBrains CVE published 2026-08-17

CVE-2026-75059

CVE-2026-75059 debrief based on the supplied source corpus. The vulnerability allows code execution via Quick Documentation in JetBrains PyCharm before 2026.2.1, with a CVSS score of 4.4. PyCharm users and administrators should verify their version and upgrade to 2026.2.1 or later to mitigate the vulnerability. The CVE record and NVD entry provide details on the vulnerability, including its severity and p [truncated]