Cross-site scripting in YouTrack - CVE-2026-86491
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in a user\'s browser.
The vulnerability exists due to stored cross-site scripting in the project and organization icon upload functionality when uploading a crafted icon file. A remote user can upload an icon file containing malicious script to execute arbitrary JavaScript in the browser of a user who views the uploaded icon.