SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86497

MEDIUM · CVSS 6.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2026.2.18769 are vulnerable to a security flaw that permits project administrators to change a mailbox host without requiring re-authentication, potentially leading to the exfiltration of stored mailbox credentials. This vulnerability could compromise sensitive information, making it critical for organizations using affected versions to prioritize updates. Users managing project administration in YouTrack should take immediate action to mitigate this risk.

CVE
CVE-2026-86497
Severity
MEDIUM
CVSS
6.8
EPSS
0.30%

Original NVD Description

In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials