ZeroHour

CVE-2026-86478

large

Unauthenticated Account Takeover in JetBrains YouTrack Helpdesk

CVSS 3.1
9.8 critical
EPSS
<1%p29
Published
()
Modified
AI analysis

CVE-2026-86478 is an improper authentication flaw (CWE-290) in the YouTrack Helpdesk component of JetBrains YouTrack. An unauthenticated remote attacker can exploit it by supplying a self-asserted (unverified) email address through the Helpdesk, bypassing proper identity validation and taking over existing helpdesk/customer accounts. Successful exploitation yields full account takeover of the affected helpdesk identity, exposing support tickets and allowing impersonation of customers (confidentiality, integrity, and availability impacts per the 9.8 CVSS score). Organizations running affected YouTrack versions with the Helpdesk module enabled are exposed, whether self-hosted or hosted. No public proof-of-concept or confirmed in-the-wild exploitation is known; EPSS puts the 30-day exploitation probability at a low 0.4% (29th percentile), and the issue is not in CISA KEV.

What to do: Upgrade YouTrack to build 2025.3.161254 (2025.3 line) or 2026.1.14042 (2026.1 line), per your installed release line. Until patched, restrict or disable unauthenticated access to the Helpdesk portal and review recently created or modified helpdesk accounts and tickets for signs of spoofed identities or unauthorized access.

Affected
JetBrains YouTrack (YouTrack Helpdesk)all versions before 2025.3.161254
JetBrains YouTrack (YouTrack Helpdesk)all versions before 2026.1.14042
Estimated exposure
large≈100,000+ users across organizations running YouTrack with the optional Helpdesk module enabled (self-hosted or JetBrains-hosted) — YouTrack is a widely deployed commercial issue tracker across self-hosted and JetBrains-cloud installations, but the flaw is confined to the optional Helpdesk component, so this is an order-of-magnitude estimate rather than a known install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.