SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86478

CRITICAL · CVSS 9.8 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2025.3.161254 and 2026.1.14042 are vulnerable to improper authentication in the Helpdesk feature, enabling unauthenticated attackers to take over accounts by asserting control over an email address. This critical vulnerability poses a significant risk to organizations using YouTrack for project management and issue tracking, as it could lead to unauthorized access and potential data breaches. Administrators should prioritize patching affected versions to mitigate this severe security threat.

CVE
CVE-2026-86478
Severity
CRITICAL
CVSS
9.8
EPSS
0.36%

Original NVD Description

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address