CVE-2026-86497: Medium severity JetBrains YouTrack vulnerability
Published Sep 7, 2026
·Updated
In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
Affected Software
1 affected component
JetBrains YouTrack<2026.2.18769
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A project administrator can exploit it. The attack requires high privileges but can be performed over the network without user interaction.
2
What versions are affected?
JetBrains YouTrack versions before 2026.2.18769 are affected.
3
What is exposed if the issue is exploited?
Stored mailbox credentials may be exfiltrated. The provided severity vector indicates a high confidentiality impact, with no stated integrity or availability impact.