Tag
#YouTrack
blogCRITICAL 9.8
CVE-2026-86478: Critical Authentication Bypass in JetBrains YouTrack
CVE-2026-86478 is a critical vulnerability in JetBrains YouTrack, allowing unauthenticated account takeover via self-asserted email addresses. With a CVSS score of 9.8, this vulnerability poses a significant risk to organizations using affected versions. Understanding the root cause and attack mechanics is crucial for defenders to implement effective mitigations.
newsHIGH 8.1
CVE-2026-75044: JetBrains YouTrack Authorization Bypass Vulnerability
A vulnerability in JetBrains YouTrack before versions 2025.3.156085, 2026.1.13914, and 2026.2.18095 allows an authenticated user to delete arbitrary entities via the mailbox endpoint due to missing authorization. This vulnerability has a CVSS score of 8.1, indicating high severity. Affected organizations should update to a patched version immediately.