SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86485

LOW · CVSS 3.3 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2026.2.18634 are vulnerable to IP spoofing through HTTP headers, enabling attackers to forge Bitbucket webhooks. This could lead to unauthorized actions being executed within the application, potentially compromising project integrity. Organizations using affected versions should prioritize this vulnerability to mitigate risks associated with unauthorized webhook interactions.

CVE
CVE-2026-86485
Severity
LOW
CVSS
3.3
EPSS
0.11%

Original NVD Description

In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks