PT-2026-58006 · Jetbrains · Youtrack

CVE-2026-62422

·

Published

2026-07-14

·

Updated

2026-07-15

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JetBrains YouTrack versions prior to 2026.1.13757 JetBrains YouTrack versions prior to 2025.3.148033 JetBrains YouTrack versions prior to 2025.2.148048 JetBrains YouTrack versions prior to 2025.1.148120 JetBrains YouTrack versions prior to 2024.3.148430 JetBrains YouTrack versions prior to 2024.2.148429
Description An authentication bypass exists in the core authentication and session handling logic. This occurs when an attacker obtains direct access to the underlying database through methods such as exposed database services, stolen credentials, or a compromised host. The issue stems from improper enforcement of authentication and authorization, as well as undue trust in the identity and session state stored in the database. By manipulating or forging authentication records, an attacker can gain full administrative access, allowing for the takeover of projects, user management, configuration changes, and widespread data exposure.
Recommendations Update to version 2026.1.13757. Update to version 2025.3.148033. Update to version 2025.2.148048. Update to version 2025.1.148120. Update to version 2024.3.148430. Update to version 2024.2.148429.

Fix

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11480
CVE-2026-62422

Affected Products

Youtrack