🔍 YouTrack REST API Authorization Gap Exposes Resources
Update affected YouTrack installations promptly and review API logs for suspicious resource access. Limit unnecessary API exposure until patched.
CVE-2026-86479 affects JetBrains YouTrack before 2026.2.18788, 2026.1.14055, and 2025.3.161254, where missing authorisation allowed access to restricted REST API resources via IDOR. The vulnerability has a CVSS score of 8.1 and is rated HIGH.
🔗 Read more 🔗
Source: NVD
🔗 YouTrack Link Controls Allow Unauthorized Entity Changes
YouTrack administrators should patch promptly to prevent unauthorized data changes. Review permissions and upgrade affected instances to a fixed release.
CVE-2026-86498 affects JetBrains YouTrack before 2025.3.160480 and 2026.1.14047, where pUT requests on link sub-resources allowed modification of linked entities without update permission. The vulnerability has a CVSS score of 7.7 and is rated HIGH.
🔗 Read more 🔗
Source: NVD
🖥️ YouTrack Whiteboard Clone Flaw Exposes Issue Links
Patch affected YouTrack deployments quickly, especially where whiteboards contain sensitive project information. Check for unexpected link changes after updating.
CVE-2026-86494 affects JetBrains YouTrack before 2026.2.18634, where cloning a whiteboard allowed unauthorized changes to links on inaccessible issues. The vulnerability has a CVSS score of 7.7 and is rated HIGH.
🔗 Read more 🔗
Source: NVD
🔑 YouTrack Token Cache Issue Enables Cross-Tenant Token Theft
Patch affected YouTrack environments as soon as possible, especially multi-tenant deployments. Investigate possible token exposure and rotate GitHub App credentials if necessary.
CVE-2026-86492 affects JetBrains YouTrack before 2026.2.18634, where a shared token cache allowed cross-tenant theft of GitHub App installation tokens. The vulnerability has a CVSS score of 8.5 and is rated HIGH.
🔗 Read more 🔗
Source: NVD
⬆️ YouTrack Group Management Bug Enables Privilege Escalation
Prioritize patching because attackers could gain elevated access through group changes. Audit privileged memberships after remediation.
CVE-2026-86482 affects JetBrains YouTrack before 2026.2.18634, where unchecked group membership changes allowed privilege escalation. The vulnerability has a CVSS score of 8.8 and is rated HIGH.
🔗 Read more 🔗
Source: NVD
🚨 JetBrains Hub Critical Bug Grants Superuser Privileges
Apply fixes immediately because unauthenticated attackers could gain full administrative control. Prioritize internet-exposed Hub deployments.
CVE-2026-86480 affects JetBrains Hub before 2026.2.52442, where an unauthenticated attacker could register a trusted service and gain superuser privileges. The vulnerability has a CVSS score of 9.8 and is rated CRITICAL.
🔗 Read more 🔗
Source: NVD
🚨 YouTrack Helpdesk Authentication Flaw Enables Account Takeover
Patch immediately because unauthenticated account takeover requires urgent remediation. Review Helpdesk accounts and authentication events after updating.
CVE-2026-86478 affects JetBrains YouTrack before 2025.3.161254 and 2026.1.14042, where improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address. The vulnerability has a CVSS score of 9.8 and is rated CRITICAL.
🔗 Read more 🔗
Source: NVD
🛡️ Dell SCG Privilege Management Flaw Raises Access Risks
Dell SCG administrators should install fixed versions soon and limit local access until patched. Review privileged activity for unexpected changes.
CVE-2026-80166 affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. The improper privilege management vulnerability could allow an unauthenticated attacker with local access to achieve elevation of privileges and has a CVSS score of 7.8 rated HIGH.
🔗 Read more 🔗
Source: NVD
📜 Dell SCG Certificate Validation Weakness Allows Access
Patch remote-accessible SCG systems promptly and verify certificate handling after updating. Monitor for unauthorized access attempts.
CVE-2026-79639 affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. The improper certificate validation vulnerability could allow an unauthenticated attacker with remote access to gain unauthorized access and has a CVSS score of 7.6 rated HIGH.
🔗 Read more 🔗
Source: NVD
💻 Dell SCG OS Command Injection Enables Privilege Abuse
Patch Dell SCG systems quickly and restrict remote administrative access until updates are applied. Validate privileged command activity after remediation.
CVE-2026-80127 affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. The OS command injection vulnerability could allow a high privileged attacker with remote access to achieve elevation of privileges and has a CVSS score of 7.2 rated HIGH.
🔗 Read more 🔗
Source: NVD
🔐 Dell SCG Certificate Bug Bypasses Protection Controls
Apply Dell updates promptly and review remote access paths to SCG systems. Confirm security controls are functioning after the upgrade.
CVE-2026-79691 affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. The improper certificate validation vulnerability could allow an unauthenticated attacker with remote access to bypass protection mechanisms and has a CVSS score of 7.3 rated HIGH.
🔗 Read more 🔗
Source: NVD
⚠️ Dell SCG Operator Handling Flaw Risks Unauthorized Access
Upgrade affected Dell SCG deployments and reduce remote exposure until patched. Check access logs for unusual authentication or operator activity.
CVE-2026-79643 affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. The use of incorrect operator vulnerability could allow an unauthenticated attacker with remote access to gain unauthorized access and has a CVSS score of 7.3 rated HIGH.
🔗 Read more 🔗
Source: NVD