CVE-2026-86478

9.8

JetBrains · YouTrack

An improper authentication vulnerability in the JetBrains YouTrack Helpdesk feature allows unauthenticated attackers to perform account takeovers by spoofing email addresses.

Executive summary

A critical authentication flaw in JetBrains YouTrack allows unauthenticated attackers to hijack user accounts, posing an extreme risk to organizational data integrity.

Vulnerability

The vulnerability stems from improper authentication handling within the YouTrack Helpdesk module (CWE-290). This flaw allows an unauthenticated attacker to bypass security controls and assume control of arbitrary user accounts by providing a self-asserted email address.

Business impact

The ability for an unauthenticated user to perform an account takeover represents a critical security failure, leading to unauthorized access to sensitive project data, internal communications, and administrative functions. Given the CVSS score of 9.8, this vulnerability allows for complete compromise of confidentiality, integrity, and availability. Successful exploitation could result in significant data breaches, loss of intellectual property, and severe reputational damage.

Remediation

Immediate Action: Upgrade JetBrains YouTrack to version 2025.3.161254, 2026.1.14042, or later immediately to resolve the authentication bypass.

Proactive Monitoring: Review system and authentication logs for anomalous account creation patterns or suspicious logins associated with the Helpdesk module.

Compensating Controls: If immediate patching is not feasible, restrict access to the YouTrack Helpdesk module at the network or Web Application Firewall (WAF) level to prevent external interaction.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability is classified as critical due to its potential for unauthenticated account takeover, which effectively bypasses all standard user-level access controls. Organizations utilizing JetBrains YouTrack must prioritize the deployment of the vendor-supplied security update to prevent unauthorized access. Failure to address this flaw leaves the entire application environment exposed to full compromise.

More JetBrains CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources