CyberRota Analysis
AI-GeneratedJetBrains YouTrack versions prior to 2026.2.18634 are vulnerable to stored cross-site scripting (XSS) attacks through the upload of project and organization icons. This vulnerability could allow an attacker to execute arbitrary scripts in the context of a user's session, potentially leading to data theft or session hijacking. Organizations using affected versions should prioritize patching to mitigate this low-severity risk, particularly those with high user interaction or sensitive data management.
CVE
CVE-2026-86491
Severity
LOW
CVSS
3.5
EPSS
0.14%
Original NVD Description
In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads