CVE-2026-86478: Critical severity JetBrains YouTrack vulnerability
Published Sep 7, 2026
·Updated
In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address
Affected Software
2 affected components
JetBrains YouTrack<2025.3.161254
JetBrains YouTrack Helpdesk=2026.1.14042
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
JetBrains YouTrack Helpdesk deployments are affected when running a version before 2025.3.161254 or 2026.1.14042.
2
What does an attacker need to exploit this issue?
The issue is exploitable remotely without authentication or user interaction. The attacker can use a self-asserted email address to take over an account.
3
What is the impact of successful exploitation?
Successful exploitation can result in account takeover. The assigned CVSS vector indicates high confidentiality, integrity, and availability impact.
4
How can I remediate the vulnerability?
Upgrade YouTrack Helpdesk to 2025.3.161254, 2026.1.14042, or a later version.