Description
In JetBrains YouTrack before 2026.1.13757,
2025.3.148033,
2025.2.148048,
2025.1.148120,
2024.3.148430,
2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
Published: 2026-07-14
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to bypass authentication in JetBrains YouTrack by directly accessing the database, resulting in administrative privileges. This weakness is reflected by CWE-306 and provides full control over the system, enabling configuration changes, data extraction, and further exploitation. The flaw carries a CVSS score of 10, indicating a very high severity.

Affected Systems

JetBrains YouTrack versions 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429 are affected.

Risk and Exploitability

With a CVSS score of 10 and an EPSS score below 1%, the overall risk is high yet the probability of exploitation is low. The issue is not listed in CISA’s KEV catalog, so no publicly known exploits exist, but the potential impact warrants immediate action. The likely attack vector involves an attacker with database access or the ability to manipulate database queries, inferred from the description. Monitoring for suspicious database activity is advisable while applying the official patch as soon as possible.

Generated by OpenCVE AI on August 1, 2026 at 10:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains YouTrack to a version that eliminates the authentication bypass
  • Review and strengthen database access controls, ensuring that only privileged accounts with strong credentials can connect
  • Implement network segmentation or firewall rules to limit which hosts can reach the database server
  • Enable auditing on the database to detect anomalous queries and review logs for signs of exploitation

Generated by OpenCVE AI on August 1, 2026 at 10:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Direct Database Access in JetBrains YouTrack

Wed, 29 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Direct Database Access in JetBrains YouTrack

Sun, 26 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Direct Database Access Grants Admin Privileges in JetBrains YouTrack

Thu, 23 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass via Direct Database Access Grants Admin Privileges in JetBrains YouTrack

Mon, 20 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass to Administrative Control via Database Access

Thu, 16 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Authentication Bypass to Administrative Control via Database Access

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-15T04:00:57.907Z

Reserved: 2026-07-14T10:16:43.594Z

Link: CVE-2026-62422

cve-icon Vulnrichment

Updated: 2026-07-14T12:05:32.907Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function