Summary
CVE-2026-86478 is a critical authentication bypass vulnerability in JetBrains YouTrack’s Helpdesk feature that allows an unauthenticated attacker to take over user accounts by supplying a self-asserted email address. The flaw carries a CVSS v3.1 base score of 9.8 (Critical) and requires no privileges or user interaction to exploit over the network.
Technical details
- Root cause: improper authentication (CWE-290, authentication bypass by spoofing) in the YouTrack Helpdesk feature, which trusts a self-asserted email address without verifying ownership.
- Trigger conditions: an attacker submits or asserts an email address associated with an existing account through the Helpdesk feature, without needing valid credentials.
- Attack vector: network-based, no authentication or user interaction required (AV:N/AC:L/PR:N/UI:N).
- Impact: full account takeover, with high impact to confidentiality, integrity, and availability (C:H/I:H/A:H).
Affected software
- JetBrains YouTrack versions prior to 2025.3.161254
- JetBrains YouTrack versions prior to 2026.1.14042
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade YouTrack to version 2025.3.161254, 2026.1.14042, or later, where the Helpdesk authentication flaw is fixed.
- If no patch can be applied immediately: restrict network access to the YouTrack Helpdesk feature/instance to trusted networks, and monitor for anomalous account changes or logins tied to Helpdesk-originated email assertions until the upgrade is completed.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
no-title="YouTrack">,type="application/opensearchdescription+xml" title="YouTrack"/>

