CVE-2026-86491: XSS
Published Sep 7, 2026
·Updated
In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads
Affected Software
1 affected component
JetBrains YouTrack<2026.2.18634
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs high privileges and user interaction. The issue is associated with uploading project or organization icons, so users able to manage those icons are the relevant threat actors.
2
Which YouTrack versions are affected?
JetBrains YouTrack versions before 2026.2.18634 are affected. Version 2026.2.18634 is not identified as affected by the provided information.
3
What is the likely impact if exploitation succeeds?
The vulnerability is stored cross-site scripting and may affect confidentiality and integrity, both rated low in the supplied vector. Availability impact is rated none.