Cross-site scripting in YouTrack - CVE-2026-86483
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim\'s browser.
The vulnerability exists due to stored cross-site scripting in custom fields on Agile board cards when displaying an Agile board card containing a crafted custom field. A remote user can inject a malicious script into a custom field to execute arbitrary script in a victim\'s browser.
User interaction is required to view the affected Agile board card.