SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86486

LOW · CVSS 3.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability in JetBrains YouTrack occurs in the generic VCS webhook handler, which fails to properly secure access when its secret is left blank, potentially allowing unauthorized access to webhook functionalities. While the CVSS score is low, organizations using affected versions should prioritize remediation to prevent potential exploitation, particularly if they rely on webhooks for version control integrations. Users should ensure that secrets are properly configured to mitigate this risk.

CVE
CVE-2026-86486
Severity
LOW
CVSS
3.7
EPSS
0.17%

Original NVD Description

In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank