Stored XSS Vulnerability in JetBrains YouTrack Affecting Project Icon Uploads
CVE-2026-86491
3.5LOW
What is CVE-2026-86491?
A stored cross-site scripting (XSS) vulnerability exists in JetBrains YouTrack prior to version 2026.2.18634, which allows attackers to upload malicious project and organization icons. This enables the execution of arbitrary scripts in the context of users accessing the affected projects. Users should ensure they are using the latest version of YouTrack to mitigate this security risk.
Affected Version(s)
YouTrack 0 < 2026.2.18634