CVE-2026-86485: Low severity JetBrains YouTrack vulnerability
Published Sep 7, 2026
·Updated
In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks
Affected Software
1 affected component
JetBrains YouTrack<2026.2.18634
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which YouTrack instances are affected?
JetBrains YouTrack versions before 2026.2.18634 are affected. Instances running 2026.2.18634 or later are not identified as affected by the provided information.
2
What does an attacker need to exploit this issue?
The attack involves spoofing an IP address through HTTP headers to forge Bitbucket webhooks. The vector indicates no attacker privileges are required, but user interaction is required.
3
What is the expected security impact?
The supplied CVSS vector rates the issue low severity and indicates low confidentiality impact. It does not indicate integrity or availability impact.