Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-86497
YouTrack vulnerability analysis and mitigation

Overview

CVE-2026-86497 is a credential disclosure vulnerability in JetBrains YouTrack that allows a project administrator to exfiltrate stored mailbox credentials by changing a mailbox host without re-authentication. It affects all YouTrack versions before 2026.2.18769 and was published on September 7, 2026. The vulnerability carries a CVSS v3.1 base score of 6.8 (Medium) (GitHub Advisory, JetBrains).

Technical details

The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data): the application transmits stored mailbox credentials to an actor who should not have access to them. Specifically, YouTrack fails to require re-authentication when a project administrator modifies the mailbox host configuration, allowing the administrator to redirect credential transmission to an attacker-controlled host and capture the stored credentials. The attack is network-based, requires no user interaction, and has a changed scope because the impact extends beyond the YouTrack application itself to the exposed mailbox credentials (GitHub Advisory).

Impact

Successful exploitation results in high confidentiality impact — a project administrator can exfiltrate stored mailbox credentials (e.g., email account usernames and passwords) configured within YouTrack. There is no integrity or availability impact. Exposed credentials could be leveraged for unauthorized access to the associated email account, potentially enabling further lateral movement or data exposure in connected systems (GitHub Advisory, JetBrains).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). Exploitation requires high privileges (project administrator access), which limits the attack surface. The EPSS score is approximately 0.267–0.298%, placing it in roughly the 22nd percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Exploitation steps

  1. Gain project administrator access: Obtain or already possess project administrator credentials for a target JetBrains YouTrack instance running a version prior to 2026.2.18769.
  2. Set up a rogue mailbox server: Deploy an attacker-controlled SMTP/IMAP server (e.g., using a simple Python SMTP listener or Postfix) to capture incoming authentication attempts.
  3. Modify mailbox host configuration: In the YouTrack project settings, navigate to the mailbox/email integration configuration and change the mailbox host to the attacker-controlled server's address — without being prompted for re-authentication.
  4. Capture transmitted credentials: When YouTrack attempts to connect to the newly configured host, it transmits the stored mailbox credentials (username and password) to the attacker-controlled server, where they are logged and captured.
  5. Use exfiltrated credentials: Leverage the captured mailbox credentials to access the victim organization's email account for further reconnaissance, phishing, or lateral movement (GitHub Advisory).

Indicators of compromise

  • Logs: YouTrack audit logs showing mailbox host configuration changes made by a project administrator account, especially to unfamiliar or external IP addresses or hostnames.
  • Network: Outbound SMTP/IMAP connection attempts from the YouTrack server to unexpected or newly configured external hosts shortly after a mailbox configuration change.
  • Application Events: YouTrack application logs recording failed or successful authentication attempts to a newly configured mailbox host that differs from the previously established mail server.

Mitigation and workarounds

JetBrains has released a patch in YouTrack version 2026.2.18769, which addresses this vulnerability by requiring re-authentication before mailbox host changes take effect. Organizations should upgrade to version 2026.2.18769 or later as the primary remediation. As interim measures, restrict project administrator privileges to trusted users only and monitor YouTrack audit logs for unexpected mailbox configuration changes (JetBrains, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related YouTrack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86497MEDIUM6.8
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86495MEDIUM6.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86500MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86499MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026
CVE-2026-86496MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesSep 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management