Mailbox Credential Exfiltration Vulnerability in JetBrains YouTrack
CVE-2026-86497
6.8MEDIUM
What is CVE-2026-86497?
In JetBrains YouTrack prior to version 2026.2.18769, a security flaw was identified where a project administrator could change the mailbox host without requiring re-authentication. This oversight permitted unauthorized exfiltration of stored mailbox credentials, potentially compromising sensitive information and exposing user data.
Affected Version(s)
YouTrack 0 < 2026.2.18769