CVE-2026-86481: Medium severity JetBrains YouTrack vulnerability
Published Sep 7, 2026
·Updated
In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
Affected Software
1 affected component
JetBrains YouTrack<2026.2.18634
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains YouTrackto a version that resolves this vulnerability.Fixed in 2026.2.18634
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access is required to exploit this issue?
An attacker needs authenticated access with low privileges and network access to the YouTrack instance. Exploitation does not require user interaction and has low attack complexity.
2
Which YouTrack deployments are affected?
JetBrains YouTrack versions before 2026.2.18634 are affected. Deployments running 2026.2.18634 or later are not identified as affected by the provided information.