VCS Webhook Handler Exposure in JetBrains YouTrack
CVE-2026-86486

3.7LOW

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86486?

A critical flaw has been identified in JetBrains YouTrack prior to version 2026.2.18634, where the webhook handler for version control systems (VCS) failed to properly restrict access when the secret was left blank. This oversight could allow unauthorized access and potential exploitation of the webhook functionality, exposing sensitive data and functions. Organizations using affected versions are urged to update to newer versions to mitigate the risk posed by this vulnerability.

Affected Version(s)

YouTrack 0 < 2026.2.18634

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.