Description
In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
Published: 2026-09-07
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains YouTrack versions prior to 2026.2.18769 allow a project administrator to change a mailbox host without re‑authentication. This flaw enables the administrator to exfiltrate the stored mailbox credentials, exposing sensitive account information. The vulnerability is an information exposure flaw identified as CWE‑201.

Affected Systems

JetBrains YouTrack before 2026.2.18769 is affected. The issue applies to all instances of YouTrack where mailbox integration is configured and used by project administrators.

Risk and Exploitability

The flaw carries a CVSS score of 6.8, indicating a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exfiltration is limited to users with project administrator privileges; no external attacker can exploit the flaw directly. The most likely attack vector involves an internal user with appropriate permissions changing the mailbox host and reading the credentials that were stored in the system.

Generated by OpenCVE AI on September 7, 2026 at 17:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains YouTrack to version 2026.2.18769 or later, which contains the fix for this issue.
  • If an upgrade is delayed, restrict project administrator privileges or disable the mailbox integration feature to block potential credential exposure.
  • Review system logs for unauthorized mailbox host changes and monitor for anomalous credential access patterns.

Generated by OpenCVE AI on September 7, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Mon, 07 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Exfiltration of Mailbox Credentials by Project Administrator in JetBrains YouTrack

Mon, 07 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-09-07T16:26:47.933Z

Reserved: 2026-09-07T16:13:39.185Z

Link: CVE-2026-86497

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T17:17:28.097

Modified: 2026-09-07T17:17:28.097

Link: CVE-2026-86497

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T17:45:17Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data