Junglewise Threat Intelligence

CVE-2026-86491: JetBrains YouTrack stored XSS in icon uploads

CVE-2026-86491 · Severity: low · CVSS 3.5 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a project and issue tracking system used by development teams to manage work and collaborate. An attacker with the ability to upload project or organization icons could inject malicious scripts that execute in the browsers of other users viewing those icons, potentially compromising user sessions or stealing sensitive project data.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in JetBrains YouTrack's icon upload functionality for projects and organizations. The vulnerability exists because uploaded icon files are not properly sanitized or validated before being displayed to other users. An authenticated attacker can upload a malicious file as a project or organization icon; the injected script then executes in the context of the victim's browser when they view the affected project or organization. The vulnerability is fixed in YouTrack version 2026.2.18634 and later.

Affected products

  • JetBrains YouTrack before 2026.2.18634

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Fixed in version 2026.2.18634

References

Related threats