PatchSiren cyber security CVE debrief
CVE-2026-86478 JetBrains CVE debrief
CVE-2026-86478 is a critical vulnerability in JetBrains YouTrack before 2025.3.161254 and 2026.1.14042, allowing unauthenticated account takeover via a self-asserted email address. This vulnerability impacts organizations using affected versions of JetBrains YouTrack, potentially allowing attackers to gain unauthorized access to user accounts. Defenders responsible for JetBrains YouTrack deployments should assess exposure and prioritize remediation to prevent potential account takeovers.
- Vendor
- JetBrains
- Product
- YouTrack
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for JetBrains YouTrack deployments, including IT administrators, security teams, and vulnerability management teams, should assess exposure and prioritize remediation. Additionally, operators and platform administrators may need to review and apply remediation patches to prevent potential account takeovers.
Why it matters
CVE-2026-86478 is a critical vulnerability in JetBrains YouTrack, allowing unauthenticated account takeover. Defenders responsible for JetBrains YouTrack deployments should assess exposure and prioritize remediation.
- Potential account takeover by unauthenticated attackers
- Verification of affected versions and remediation priority
Technical summary
CVE-2026-86478 is a critical vulnerability in JetBrains YouTrack before 2025.3.161254 and 2026.1.14042, allowing unauthenticated account takeover via a self-asserted email address. This vulnerability impacts organizations using affected versions of JetBrains YouTrack, potentially allowing attackers to gain unauthorized access to user accounts. The vulnerability is related to improper authentication in YouTrack Helpdesk.
Defensive priority
Defenders should prioritize verification of affected versions and remediation.
Recommended defensive actions
- Verify affected versions of JetBrains YouTrack
- Review and apply remediation patches
- Monitor for potential account takeover attempts
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. The CVE Program record (CVE-2026-86478) and NVD detail page (CVE-2026-86478) offer source-provided CVE metadata and source-specific vulnerability assessments. However, additional details about the vulnerability's impact, exploitation, and affected systems are not provided. Defenders should verify affected versions and review remediation patches. The source reference (ref-3) may offer further context onJet
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86478 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86478
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86478 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86478
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jetbrains.com/privacy-security/issues-fixed/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.