Junglewise Threat Intelligence

CVE-2026-86497: JetBrains YouTrack mailbox credential exfiltration

CVE-2026-86497 · Severity: medium · CVSS 6.8 · Published 2026-09-07

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack is a project management and issue tracking system used by development teams. A vulnerability allows project administrators to change mailbox host configuration settings without re-authenticating, potentially enabling them to extract stored mailbox credentials. This could lead to unauthorized access to email accounts and sensitive communications.

Technical details

The vulnerability is an authentication bypass in the mailbox configuration functionality of YouTrack. A project administrator can modify mailbox host settings without undergoing re-authentication, allowing exfiltration of stored mailbox credentials. The attack requires project administrator privileges and does not require network access beyond the YouTrack web interface. An attacker with these privileges can extract plaintext or weakly protected credentials used for email integration. The vulnerability is fixed in YouTrack version 2026.2.18769 and later.

Affected products

  • JetBrains YouTrack before 2026.2.18769

Timeline

  • 2026-09-07: disclosed

References

Related threats