CyberRota Analysis
AI-GeneratedThe vulnerability in JetBrains YouTrack occurs in the generic VCS webhook handler, which fails to properly secure access when its secret is left blank, potentially allowing unauthorized access to webhook functionalities. While the CVSS score is low, organizations using affected versions should prioritize remediation to prevent potential exploitation, particularly if they rely on webhooks for version control integrations. Users should ensure that secrets are properly configured to mitigate this risk.
CVE
CVE-2026-86486
Severity
LOW
CVSS
3.7
EPSS
0.17%
Original NVD Description
In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank