Junglewise Threat Intelligence

CVE-2026-86483: JetBrains YouTrack stored XSS in custom field on Agile board

CVE-2026-86483 · Severity: medium · CVSS 5.4 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a project tracking and issue management system used by development teams. A stored cross-site scripting (XSS) vulnerability in the Agile board feature allows attackers to inject malicious scripts through custom fields, which could be executed when other team members view the board, potentially compromising their session or stealing sensitive information.

Technical details

The vulnerability is a stored XSS flaw in JetBrains YouTrack's Agile board custom field handling, where user-supplied input is not properly sanitized before being displayed to other users. An attacker with the ability to edit custom fields on Agile board cards can inject malicious JavaScript that persists in the application and executes in the browsers of any user viewing the affected board. This requires authenticated access to YouTrack but no special privileges. The vulnerability has been fixed in YouTrack version 2026.2.18634 and later.

Affected products

  • JetBrains YouTrack before 2026.2.18634

Timeline

  • 2026-09-07: disclosed

References

Related threats