CVE-2026-62422
Awaiting Analysis Awaiting Analysis - Queue

Authentication Bypass in JetBrains YouTrack

Vulnerability report for CVE-2026-62422, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-15

Assigner: JetBrains s.r.o.

Description

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-15
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
jetbrains youtrack to 2026.1.13757 (exc)
jetbrains youtrack to 2025.3.148033 (exc)
jetbrains youtrack to 2025.2.148048 (exc)
jetbrains youtrack to 2025.1.148120 (exc)
jetbrains youtrack to 2024.3.148430 (exc)
jetbrains youtrack to 2024.2.148429 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-62422 is an authentication bypass vulnerability in JetBrains YouTrack, a project management and issue tracking tool. The vulnerability allows an attacker to bypass authentication mechanisms by directly accessing the database, which can lead to unauthorized administrative access.

This issue affects multiple versions of YouTrack released before specific patches: 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429. The vulnerability is classified as critical, with a CVSS v3.1 base score of 10.0, indicating severe impact.

Detection Guidance

Detecting this vulnerability requires checking the installed version of JetBrains YouTrack on your system. The vulnerability affects specific versions before the following patched releases: 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429.

To verify the installed version, you can:

  • Check the YouTrack web interface: Log in as an administrator, navigate to the 'Administration' section, and look for the version information in the system settings or about page.
  • Inspect the installation directory: If you have access to the server where YouTrack is installed, check the version file or configuration files for version details. For example, on a Linux system, you might find version information in a file like /opt/youtrack/conf/internal/bundle.properties.

If your installed version matches any of the affected versions listed in the CVE description, your system may be vulnerable.

Impact Analysis

If you are using an affected version of JetBrains YouTrack, this vulnerability could have serious consequences, including:

  • Unauthorized access to sensitive project data, issue details, and user information stored in YouTrack.
  • Administrative control of the YouTrack instance, allowing an attacker to modify, delete, or exfiltrate data.
  • Potential lateral movement within your network if YouTrack is integrated with other systems or services.
  • Disruption of project management operations, leading to downtime or loss of productivity.

The CVSS score of 10.0 indicates that the vulnerability is exploitable remotely without requiring any privileges or user interaction, making it highly dangerous.

Compliance Impact

This vulnerability can significantly impact compliance with various standards and regulations, depending on the data stored in YouTrack and the applicable legal frameworks:

  • GDPR (General Data Protection Regulation): If YouTrack contains personal data of EU citizens, unauthorized access could lead to a data breach. GDPR requires organizations to implement appropriate security measures and report breaches within 72 hours. Failure to patch this vulnerability could result in non-compliance, fines, and reputational damage.
  • HIPAA (Health Insurance Portability and Accountability Act): If YouTrack is used to manage healthcare-related projects or contains protected health information (PHI), this vulnerability could lead to a breach of PHI. HIPAA mandates strict controls over access to such data, and exploitation of this vulnerability could result in violations and penalties.
  • ISO 27001: This standard requires organizations to manage information security risks. The presence of an unpatched critical vulnerability like this could indicate a failure in risk management processes, potentially leading to non-compliance during audits.
  • SOC 2: If your organization undergoes SOC 2 audits, this vulnerability could impact the security and confidentiality trust services criteria. Unauthorized access to sensitive data could result in a failed audit or loss of certification.

Organizations must patch this vulnerability promptly to avoid compliance violations and potential legal or financial consequences.

Mitigation Strategies

To mitigate this vulnerability, follow these immediate steps:

  • Upgrade JetBrains YouTrack to the latest patched version as soon as possible. The fixed versions are 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, or 2024.2.148429, depending on your current release line.
  • Restrict direct database access to YouTrack. Ensure that only authorized personnel and services can access the database, and use network-level controls (e.g., firewalls) to limit access to the database port.
  • Monitor for unusual activity: Review logs for signs of unauthorized access or authentication bypass attempts. Pay special attention to administrative actions performed without proper authentication.
  • Isolate the YouTrack instance: If upgrading is not immediately possible, consider isolating the YouTrack server from untrusted networks until the patch can be applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62422. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart