Stored XSS Vulnerability in JetBrains YouTrack Affecting Project Icon Uploads
CVE-2026-86491

3.5LOW

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
7 September 2026

What is CVE-2026-86491?

A stored cross-site scripting (XSS) vulnerability exists in JetBrains YouTrack prior to version 2026.2.18634, which allows attackers to upload malicious project and organization icons. This enables the execution of arbitrary scripts in the context of users accessing the affected projects. Users should ensure they are using the latest version of YouTrack to mitigate this security risk.

Affected Version(s)

YouTrack 0 < 2026.2.18634

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.