VCS Webhook Handler Exposure in JetBrains YouTrack
CVE-2026-86486
3.7LOW
What is CVE-2026-86486?
A critical flaw has been identified in JetBrains YouTrack prior to version 2026.2.18634, where the webhook handler for version control systems (VCS) failed to properly restrict access when the secret was left blank. This oversight could allow unauthorized access and potential exploitation of the webhook functionality, exposing sensitive data and functions. Organizations using affected versions are urged to update to newer versions to mitigate the risk posed by this vulnerability.
Affected Version(s)
YouTrack 0 < 2026.2.18634