Executive brief
JetBrains YouTrack, a project management and issue tracking tool, is affected by a critical security flaw that allows unauthorized individuals to bypass authentication. By exploiting this vulnerability, an attacker could gain full administrative control over the system without needing a password. This could lead to the theft of sensitive project data, disruption of business operations, and total compromise of the application environment.
Technical details
An authentication bypass vulnerability exists in JetBrains YouTrack due to missing authentication for critical functions (CWE-306). The flaw allows an unauthenticated attacker to gain administrative access via direct database access mechanisms. The vulnerability is exploitable over the network with low complexity and requires no user interaction. Successful exploitation grants the attacker full control over the YouTrack instance. The issue is resolved in versions 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429.
Affected products
- JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429
Timeline
- 2026-07-14: advisory: Initial advisory publication by JetBrains and NVD.
- 2026-07-14: patched: Fixes released in multiple version branches.