CVE-2026-86478
largeUnauthenticated Account Takeover in JetBrains YouTrack Helpdesk
CVE-2026-86478 is an improper authentication flaw (CWE-290) in the YouTrack Helpdesk component of JetBrains YouTrack. An unauthenticated remote attacker can exploit it by supplying a self-asserted (unverified) email address through the Helpdesk, bypassing proper identity validation and taking over existing helpdesk/customer accounts. Successful exploitation yields full account takeover of the affected helpdesk identity, exposing support tickets and allowing impersonation of customers (confidentiality, integrity, and availability impacts per the 9.8 CVSS score). Organizations running affected YouTrack versions with the Helpdesk module enabled are exposed, whether self-hosted or hosted. No public proof-of-concept or confirmed in-the-wild exploitation is known; EPSS puts the 30-day exploitation probability at a low 0.4% (29th percentile), and the issue is not in CISA KEV.
What to do: Upgrade YouTrack to build 2025.3.161254 (2025.3 line) or 2026.1.14042 (2026.1 line), per your installed release line. Until patched, restrict or disable unauthenticated access to the Helpdesk portal and review recently created or modified helpdesk accounts and tickets for signs of spoofed identities or unauthorized access.
| JetBrains YouTrack (YouTrack Helpdesk) | all versions before 2025.3.161254 |
| JetBrains YouTrack (YouTrack Helpdesk) | all versions before 2026.1.14042 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address
- Weakness
- CWE-290
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.