Improper Authentication in JetBrains YouTrack Helpdesk Allows Unauthorized Access
CVE-2026-86478

9.8CRITICAL

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86478?

In JetBrains YouTrack Helpdesk, versions prior to 2025.3.161254 and 2026.1.14042, an improper authentication flaw allows malicious users to exploit unauthenticated access. This vulnerability enables attackers to gain unauthorized account access by asserting a controlled email address, potentially leading to account takeover and data exposure.

Affected Version(s)

YouTrack 0 < 2025.3.161254, 2026.1.14042

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.