Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-62422: YouTrack: Unauthorized Access to Administrative Features

CVE-2026-62422 CVE-2026-62422
Summary

An old version of YouTrack allowed attackers to bypass authentication and gain access to administrative features by directly accessing the database. This could have allowed hackers to make changes to the system without being authorized. Update to the latest version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
jetbrains youtrack < 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429
Original title
In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative acces...
Original description
In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
mitre CVSS3.1 10.0
Vulnerability type
CWE-306 Missing Authentication for Critical Function
Published: 14 Jul 2026 · Updated: 20 Jul 2026 · First seen: 14 Jul 2026