Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5601 articles · 220742 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-86478PATCHED
jetbrains · youtrack

CVE-2026-86478: In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthent

Description

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

Affected Products

VendorProductVersions
jetbrainsyoutrack0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
jetbrainsyou trackcert_advisory90%

References

  • https://www.jetbrains.com/privacy-security/issues-fixed/

Related News (2 articles)

Tier B
BSI Advisories14d ago
[NEU] [hoch] JetBrains You Track: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB14d ago
CVE-2026-86478 | JetBrains YouTrack prior 2025.3.161254/2026.1.14042 Helpdesk improper authentication
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
2025.3.1612542026.1.14042
CWECWE-290
PublishedSep 7, 2026
Last enriched14d ago
Trending Score12
Source articles2
Independent2
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-63077EXPKEV
CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
Trending: 16
CRITICALCVE-2026-86480
CVE-2026-86480: In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser pri
Trending: 9
HIGHCVE-2026-86482
CVE-2026-86482: In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation
Trending: 9
HIGHCVE-2026-86479
CVE-2026-86479: In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restric
Trending: 9
HIGHCVE-2026-86504
CVE-2026-86504: In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed ho
Trending: 9

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 7, 2026
Discovered by ZDM
Sep 7, 2026
Patch Available
Sep 9, 2026