CVE-2026-86497

Summary

In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials

Affected Software

VendorProductVersion RangeStatus
JetBrainsYouTrack0 < 2026.2.18769affected

Weaknesses

  • CWE-201: CWE-201

References