
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86497 is a credential disclosure vulnerability in JetBrains YouTrack that allows a project administrator to exfiltrate stored mailbox credentials by changing a mailbox host without re-authentication. It affects all YouTrack versions before 2026.2.18769 and was published on September 7, 2026. The vulnerability carries a CVSS v3.1 base score of 6.8 (Medium) (GitHub Advisory, JetBrains).
The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data): the application transmits stored mailbox credentials to an actor who should not have access to them. Specifically, YouTrack fails to require re-authentication when a project administrator modifies the mailbox host configuration, allowing the administrator to redirect credential transmission to an attacker-controlled host and capture the stored credentials. The attack is network-based, requires no user interaction, and has a changed scope because the impact extends beyond the YouTrack application itself to the exposed mailbox credentials (GitHub Advisory).
Successful exploitation results in high confidentiality impact — a project administrator can exfiltrate stored mailbox credentials (e.g., email account usernames and passwords) configured within YouTrack. There is no integrity or availability impact. Exposed credentials could be leveraged for unauthorized access to the associated email account, potentially enabling further lateral movement or data exposure in connected systems (GitHub Advisory, JetBrains).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). Exploitation requires high privileges (project administrator access), which limits the attack surface. The EPSS score is approximately 0.267–0.298%, placing it in roughly the 22nd percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
JetBrains has released a patch in YouTrack version 2026.2.18769, which addresses this vulnerability by requiring re-authentication before mailbox host changes take effect. Organizations should upgrade to version 2026.2.18769 or later as the primary remediation. As interim measures, restrict project administrator privileges to trusted users only and monitor YouTrack audit logs for unexpected mailbox configuration changes (JetBrains, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."