Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-62422 -- CVSS 10.0 Vulnerability Briefing

CVE-2026-62422 | CVSS 10.0 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-62422 is a critical authentication bypass vulnerability in JetBrains YouTrack, a project management and issue tracking platform, that allows unauthenticated or low-privileged attackers to gain administrative access through direct database access.

Technical Detail

The flaw exists in multiple YouTrack release branches and permits an attacker to bypass authentication controls by interacting directly with the underlying database layer, circumventing the application's normal access enforcement. Successful exploitation grants full administrative access to the YouTrack instance, which could expose all project data, user credentials, internal tickets, and integration secrets stored within the platform. The vulnerability is present in versions prior to 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429, indicating a broad range of affected deployments across multiple long-term support branches.

Exploitation Status

No known exploit code has been publicly observed or confirmed at this time. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Despite the absence of confirmed exploitation, the CVSS score of 10.0 and the nature of the flaw warrant treating this as a high-priority patching target regardless of current exploit activity.

Who Is Targeting This

No specific threat actor attribution at this time. No confirmed or reported threat actor activity has been associated with this CVE as of the date of this briefing.

What To Do

Organizations running JetBrains YouTrack should update immediately to the patched versions: 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, or 2024.2.148429, depending on the branch in use. Given the CVSS 10.0 rating and the administrative access impact, this should be treated as an emergency patch with no grace period. If immediate patching is not possible, restrict network access to YouTrack instances to trusted internal networks or VPN-only access, and disable any public-facing exposure of the application. Administrators should audit YouTrack access logs for anomalous database-level activity or unexpected administrative account creation as potential indicators of prior exploitation. Review all administrative accounts and API tokens for signs of unauthorized additions or modifications.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →