Junglewise Threat Intelligence

CVE-2026-86496: JetBrains YouTrack missing access control on Helpdesk authorized reporters

CVE-2026-86496 · Severity: medium · CVSS 4.3 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a project management and issue tracking system used by development teams to manage work and customer support requests. A missing access control flaw allows unauthorized users to view email addresses of users designated as Helpdesk authorized reporters, potentially exposing sensitive contact information and enabling social engineering attacks.

Technical details

The vulnerability is a missing access control (broken authorization) in the Helpdesk module of JetBrains YouTrack versions before 2026.2.18769. The flaw allows unauthenticated or inadequately authenticated users to access and enumerate email addresses of users assigned the Helpdesk authorized reporter role. The vulnerability is network-accessible and requires no special preconditions to trigger. An attacker can retrieve sensitive reporter contact information, which may be used for targeted social engineering or account compromise. The issue has been fixed in version 2026.2.18769 and later.

Affected products

  • JetBrains YouTrack before 2026.2.18769

Timeline

  • 2026-09-07: disclosed
  • 2026-2-187: patched

References

Related threats