CyberRota Analysis
AI-GeneratedJetBrains YouTrack versions prior to 2026.2.18634 are vulnerable to a stored cross-site scripting (XSS) attack due to an AngularJS template injection in assignee names. This vulnerability could allow attackers to execute arbitrary scripts in the context of the affected application, potentially compromising user data and session integrity. Organizations using YouTrack should prioritize patching this vulnerability to mitigate the risk of exploitation.
CVE
CVE-2026-86484
Severity
MEDIUM
CVSS
4.6
EPSS
0.38%
Original NVD Description
In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS