Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-62422: YouTrack: Unauthorized Access to Administrative Features
CVE-2026-62422
CVE-2026-62422
Summary
An old version of YouTrack allowed attackers to bypass authentication and gain access to administrative features by directly accessing the database. This could have allowed hackers to make changes to the system without being authorized. Update to the latest version to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jetbrains | youtrack | < 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 |
Original title
In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative acces...
Original description
In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
mitre CVSS3.1
10.0
Vulnerability type
CWE-306
Missing Authentication for Critical Function
Published: 14 Jul 2026 · Updated: 20 Jul 2026 · First seen: 14 Jul 2026