CVE-2026-25846: Medium severity JetBrains YouTrack vulnerability
Published Feb 9, 2026
·Updated
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
Affected Software
2 affected components
JetBrains YouTrack<2025.3.119033
JetBrains YouTrack<2025.3.119033
Event History
Feb 9, 2026
CVE Published
via MITRE·10:38 AM
Data Sourced
via MITRE·10:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-25846?
CVE-2026-25846 is considered a high severity vulnerability due to the potential exposure of sensitive access tokens.
2
How do I fix CVE-2026-25846?
To fix CVE-2026-25846, you should upgrade JetBrains YouTrack to version 2025.3.119033 or later.
3
What types of access tokens are affected by CVE-2026-25846?
CVE-2026-25846 affects access tokens that may be logged in Mailbox logs of JetBrains YouTrack.
4
Who is affected by CVE-2026-25846?
Any organization using JetBrains YouTrack versions prior to 2025.3.119033 is at risk due to CVE-2026-25846.
5
What should I do if I cannot upgrade my JetBrains YouTrack version immediately due to CVE-2026-25846?
If an immediate upgrade is not possible, consider implementing additional logging security measures and monitoring access to limit exposure.