The JetBrains Blog

Security Issue in YouTrack (CVE-2026-33392): Upgrade Recommended for Server Versions Before 2025.3.132953

5.5内容质量
Security Issue in YouTrack (CVE-2026-33392): Upgrade Recommended for Server Versions Before 2025.3.132953

TL;DR · AI 摘要

JetBrains 发布安全通告,YouTrack 服务器版本低于 2025.3.132953 存在 CVE-2026-33392 漏洞,建议立即升级。

核心要点

  • YouTrack 旧版本存在安全漏洞 CVE-2026-33392
  • 受影响版本为 2025.3.132953 之前的所有服务器版
  • 官方建议用户尽快升级以修复该漏洞
#YouTrack#JetBrains#CVE#安全漏洞#软件升级
打开原文

Security Issue in YouTrack (CVE-2026-33392): Upgrade Recommended for Server Versions Before 2025.3.132953 | The YouTrack Blog

[](http://blog.jetbrains.com/youtrack/2026/04/security-issue-in-youtrack-cve-2026-33392/#)

Cookie Settings

Our website uses some cookies and records your IP address for the purposes of accessibility, security, and managing your access to the telecommunication network. You can disable data collection and cookies by changing your browser settings, but it may affect how this website functions. Learn more

With your consent, JetBrains may also use cookies and your IP address to collect individual statistics and provide you with personalized offers and ads subject to the Privacy Notice and the Terms of Use. JetBrains may use third-party services for this purpose. You can adjust or withdraw your consent at any time by visiting the Opt-Out.

Accept All Manage Settings

[![Image 2](https://blog.jetbrains.com/wp-content/uploads/2024/06/JETBRAINS-Blog.svg)](https://blog.jetbrains.com/)Skip to content

Burger menu icon

  • #### IDEs
  • [CLion](http://blog.jetbrains.com/clion/ "CLion Blog")
  • [DataGrip](http://blog.jetbrains.com/datagrip/ "DataGrip Blog")
  • DataSpell
  • [GoLand](http://blog.jetbrains.com/go/ "GoLand Blog")
  • [IntelliJ IDEA](http://blog.jetbrains.com/idea/ "IntelliJ IDEA Blog")
  • [PhpStorm](http://blog.jetbrains.com/phpstorm/ "PhpStorm Blog")
  • [PyCharm](http://blog.jetbrains.com/pycharm/ "PyCharm Blog")
  • RustRover
  • [Rider](http://blog.jetbrains.com/dotnet/tag/rider/ "Rider Blog")
  • [RubyMine](http://blog.jetbrains.com/ruby/ "RubyMine Blog")
  • [WebStorm](http://blog.jetbrains.com/webstorm/ "WebStorm Blog")
  • #### Plugins & Services
  • #### Team Tools
  • #### .NET & Visual Studio
  • [.NET Tools](http://blog.jetbrains.com/dotnet/ ".NET Tools")
  • [ReSharper C++](http://blog.jetbrains.com/rscpp/ "ReSharper C++ Blog")
  • #### Languages & Frameworks
  • [Kotlin](http://blog.jetbrains.com/kotlin/ "Kotlin Blog")
  • Ktor
  • [MPS](http://blog.jetbrains.com/mps/ "MPS Blog")
  • Amper
  • #### Education & Research
  • #### Company

![Image 3: Youtrack logo ## YouTrack](https://blog.jetbrains.com/youtrack/) Powerful project management for all your teams

Follow

Get YouTrack for free

YouTrack

Security Issue in YouTrack (CVE-2026-33392): Upgrade Recommended for Server Versions Before 2025.3.132953

Image 4: Elena Pishkova
Image 4: Elena Pishkova

Elena Pishkova

April 17, 2026

A security vulnerability in YouTrack came to light in March 2026, and we fixed it immediately. Most of you don’t need to do anything, but we want to keep you informed. For most YouTrack administrators, this is purely an informational post.

  • We have already upgraded YouTrack Cloud to a new version.
  • YouTrack Server instances on version 2025.3.132953 or later are not affected.

**Action required from YouTrack Server administrators**Copy heading link

If you are running YouTrack Server on a version older than 2025.3.132953, we recommend upgrading to any version available to you, starting from 2025.3.132953, as soon as possible.

You can check your current version in _Administration | Server Settings | Global Settings_. To see which versions are available under your license, check the_License Details_ section in the settings or visit yourJetBrains Account. To upgrade, download the latest available version from theYouTrack download page, or pick a specific build from theprevious versions page. For upgrade instructions, refer to theInstallation and Upgrade documentation.

**The vulnerability: summary**Copy heading link

In March 2026, a security researcher from the Hacktron AI team identified a vulnerability and reported it to us through our coordinated disclosure policy. The core issue was a sandbox bypass that could allow code execution and required administrator-level permissions to exploit.

The vulnerability has been assigned the identifier CVE-2026-33392. It affected all YouTrack versions before 2025.3.132953.

The impact was most significant in YouTrack Cloud, allowing bypassing the cross-tenant isolation boundaries for tenants sharing the same hardware.

YouTrack Server is a single-tenant solution, meaning that it’s not possible to access anything that does not already belong to the server owner. At the same time, the vulnerability requires administrative permissions to exploit.

**Mitigation**Copy heading link

We implemented mitigation measures within 48 hours of receiving the report.

YouTrack Cloud servers were patched, and we have found no evidence that the vulnerability was ever exploited.

For YouTrack Server, the fix is included in version 2025.3.132953 and all later versions. There are no tenant boundaries in YouTrack Server, but the vulnerability may still allow permission escalation within administrative roles.

**Security bulletin**Copy heading link

A complete list of recently fixed security issues is available on theFixed Security Issues page on the JetBrains website. You can alsosubscribe to receive email notifications about security fixes across all JetBrains products.

**Frequently asked questions**Copy heading link

Which versions are affected?Copy heading link

All YouTrack versions before 2025.3.132953 were affected.

Is the YouTrack Server affected?Copy heading link

Yes, but to a much lesser extent than YouTrack Cloud. YouTrack Server is a single-tenant solution, so there are no cross-tenant boundaries at risk. The vulnerability requires administrative permissions to exploit and may allow permission escalation within administrative roles. If you are already on version 2025.3.132953 or later, no action is needed.

Was my data compromised?Copy heading link

We have found no evidence that the vulnerability was ever exploited in any environment.

**Support**Copy heading link

If you have any questions regarding this issue, please get in touch with the YouTrack Support team.

_Your YouTrack team_

Newssecurity

_Prev post_ YouTrack Introduces Whiteboards

#### Subscribe to YouTrack Blog updates

Subscribe form

By submitting this form, I agree to the JetBrains Privacy Policy _Notification icon_

By submitting this form, I agree that JetBrains s.r.o. ("JetBrains") may use my name, email address, and location data to send me newsletters, including commercial communications, and to process my personal data for this purpose. I agree that JetBrains may process said data using third-party services for this purpose in accordance with the JetBrains Privacy Policy. I understand that I can revoke this consent at any time in my profile. In addition, an unsubscribe link is included in each email.

Submit

Thanks, we've got you!

[](http://blog.jetbrains.com/youtrack/2026/04/security-issue-in-youtrack-cve-2026-33392/#)

  1. Action required from YouTrack Server administrators
  2. The vulnerability: summary
  3. Mitigation
  4. Security bulletin
  5. Frequently asked questions
  6. Which versions are affected?
  7. Is the YouTrack Server affected?
  8. Was my data compromised?
  1. Support

Discover more

![Image 5 #### New YouTrack Prices Starting from October 2025 We’re introducing a few changes to YouTrack prices, which will take effect on October 1, 2025. Read on to learn about the reasons for this change, how to prepare, and what it means for YouTrack Cloud and Server customers. Image 6: Elena Pishkova Elena Pishkova June 30, 2025 1](https://blog.jetbrains.com/youtrack/2025/06/new-youtrack-prices-starting-from-october-2025/)

![Image 7 #### Discontinuing the Legacy REST API: Action Required This post is a reminder about important changes to the technical aspects of building external integrations with YouTrack, as well as the actions that YouTrack administrators and those in charge of setting external integrations for your teams must take by the end of June 2021. What is changing? Two y… Image 8: Anastasia Bartasheva Anastasia Bartasheva February 17, 2021 11](https://blog.jetbrains.com/youtrack/2021/02/discontinuing-the-legacy-rest-api-action-required/)

![Image 9: YouTrack 2021 Roadmap #### What’s Next: YouTrack 2021 Roadmap It's the start of a new year, and what better time than now to tell you about the plans we have for it. We’re constantly looking into feedback from more than 50,000 teams that are using YouTrack. This input helps us understand the current trends in project management and what features we should focu… Image 10: Elena Pishkova Elena Pishkova January 28, 2021 0](https://blog.jetbrains.com/youtrack/2021/01/what-s-next-youtrack-2021-roadmap/)

![Image 11 #### Gartner Digital Markets Ranks YouTrack Among the Top Software Tools in Its Category As the year draws to an end, we’ve received some good news about the yearly ranking of issue tracking tools from Gartner Digital Markets. YouTrack is one of 2020’s top 10 category leaders in Bug Tracking Software according to GetApp, as well as one of the top bug-tracking products in Software Advic… Image 12: Pavel Kitovkin Pavel Kitovkin November 26, 2020 0](https://blog.jetbrains.com/youtrack/2020/11/gartner-digital-markets-ranks-youtrack-among-the-top-software-tools-in-its-category/)

_Merchandise store icon_ Merchandise store

Copyright © 2000 JetBrains s.r.o.

Image 13%3A%20Upgrade%20Recommended%20for%20Server%20Versions%20Before%202025.3.132953%20%7C%20The%20YouTrack%20Blog&p=https%3A%2F%2Fblog.jetbrains.com%2Fyoutrack%2F2026%2F04%2Fsecurity-issue-in-youtrack-cve-2026-33392%2F&r=&lt=2147&pt=1776433675611,,,,,36,36,36,36,36,,36,51,51,64,808,839,1213,2145,2145,2147&pn=0,0&evt=pageLoad&sv=2&asc=G&cdb=AQAS&rn=722861)

Image 14%3A%20Upgrade%20Recommended%20for%20Server%20Versions%20Before%202025.3.132953%20%7C%20The%20YouTrack%20Blog&tw_document_href=https%3A%2F%2Fblog.jetbrains.com%2Fyoutrack%2F2026%2F04%2Fsecurity-issue-in-youtrack-cve-2026-33392%2F&tw_iframe_status=0&tw_pid_src=1&twpid=tw.1776433678421.327058024171870987&txn_id=nv3vm&type=javascript&version=2.3.52)Image 15%3A%20Upgrade%20Recommended%20for%20Server%20Versions%20Before%202025.3.132953%20%7C%20The%20YouTrack%20Blog&tw_document_href=https%3A%2F%2Fblog.jetbrains.com%2Fyoutrack%2F2026%2F04%2Fsecurity-issue-in-youtrack-cve-2026-33392%2F&tw_iframe_status=0&tw_pid_src=1&twpid=tw.1776433678421.327058024171870987&txn_id=nv3vm&type=javascript&version=2.3.52)