IP Spoofing Vulnerability in JetBrains YouTrack
CVE-2026-86485

3.5LOW

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86485?

In JetBrains YouTrack, prior to version 2026.2.18634, an IP spoofing vulnerability allowed malicious actors to forge Bitbucket webhooks through manipulated HTTP headers. This vulnerability poses a risk to the authenticity of webhook communications, potentially leading to unauthorized access and actions within the affected systems. Users are urged to upgrade to the latest version to mitigate this security risk.

Affected Version(s)

YouTrack 0 < 2026.2.18634

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.