PT-2026-58006 · Jetbrains · Youtrack
CVE-2026-62422
·
Published
2026-07-14
·
Updated
2026-07-15
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JetBrains YouTrack versions prior to 2026.1.13757
JetBrains YouTrack versions prior to 2025.3.148033
JetBrains YouTrack versions prior to 2025.2.148048
JetBrains YouTrack versions prior to 2025.1.148120
JetBrains YouTrack versions prior to 2024.3.148430
JetBrains YouTrack versions prior to 2024.2.148429
Description
An authentication bypass exists in the core authentication and session handling logic. This occurs when an attacker obtains direct access to the underlying database through methods such as exposed database services, stolen credentials, or a compromised host. The issue stems from improper enforcement of authentication and authorization, as well as undue trust in the identity and session state stored in the database. By manipulating or forging authentication records, an attacker can gain full administrative access, allowing for the takeover of projects, user management, configuration changes, and widespread data exposure.
Recommendations
Update to version 2026.1.13757.
Update to version 2025.3.148033.
Update to version 2025.2.148048.
Update to version 2025.1.148120.
Update to version 2024.3.148430.
Update to version 2024.2.148429.
Fix
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Youtrack