CVE-2026-86487

In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content

  • Published Sep 7, 2026
  • CVSS 3.1 low
  • 0.2% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-86487 at the National Vulnerability Database