惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
U
Unit 42
A
About on SuperTechFans
Vercel News
Vercel News
B
Blog
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
腾讯CDC
D
Docker
V
Visual Studio Blog
博客园 - 叶小钗
The Cloudflare Blog
Jina AI
Jina AI
B
Blog RSS Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
T
Tailwind CSS Blog
MongoDB | Blog
MongoDB | Blog
D
DataBreaches.Net
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏

The JetBrains Blog

Kotlin Turns 15: Celebrate the Kotlin Effect - The JetBrains Blog PhpStorm 2026.2 is Now Out - The JetBrains Blog Key Takeaways From PHPverse 2026 - The JetBrains Blog What's New in IntelliJ IDEA 2026.2 - The JetBrains Blog What’s fixed in IntelliJ IDEA 2026.2 - The JetBrains Blog CLion 2026.2 Is Here - The JetBrains Blog DataGrip 2026.2: AI Agent Skills, MCP Tools and CLI Commands for Data Source Management, Bundled JDBC Drivers, and Improved Session Control - The JetBrains Blog Download WebStorm 2026.2: TypeScript 7 Support, AI, and more GoLand 2026.2 Is Now Available! - The JetBrains Blog Code in Space: Redefining Tech Creation with AI and XR - The JetBrains Blog Rider 2026.2 Release Candidate Is Out! - The JetBrains Blog ReSharper 2026.2 Release Candidate Released! - The JetBrains Blog JetBrains GameDev Days 2026 – Call for Speakers - The JetBrains Blog MPS 2026.1 Has Been Released! - The JetBrains Blog IntelliJ Scala Plugin 2026.2 Is Out! - The JetBrains Blog What's New in ReSharper 2026.2 for VS Code-compatible editors  - The JetBrains Blog Debugging for .NET in VS Code and Cursor: The #1 Requested Feature Is Here - The JetBrains Blog dotInsights | July 2026 - The JetBrains Blog The History of Kodee, Kotlin’s Mascot - The JetBrains Blog JetBrains Academy – June Digest - The JetBrains Blog Introducing the Kotlin Benchmark for AI Coding Agents - The JetBrains Blog Best Object Detection Models for Machine Learning in 2026 - The JetBrains Blog What's Next for TeamCity – CI/CD by JetBrains - The JetBrains Blog The Benchmark Meaning Gap - The JetBrains Blog JetBrains AI for Teams and Organizations: From Fragmented AI Usage to Coordinated Software Development - The JetBrains Blog Java Annotated Monthly – July 2026  - The JetBrains Blog Shift-Left with JetBrains Qodana Natvis Comes to Linux and macOS: Visualize Your C++ Types Without Writing a Single Data Formatter - The JetBrains Blog Speaking to AI Agents like Cavemen Saves 65% of Tokens. We Test. In Conversation With the Golden Kodee Winners - The JetBrains Blog
YouTrack Security Update: Upgrade Required for YouTrack S...
Elena Pishkova · 2026-06-19 · via The JetBrains Blog

Security YouTrack

YouTrack Security Update: Upgrade Required for YouTrack Server

We’re sharing this update to inform YouTrack administrators about several security vulnerabilities that were recently identified and fixed in YouTrack.

For YouTrack Cloud users, this post is purely informational – YouTrack Cloud has already been patched and no action is required. 

For YouTrack Server administrators, we recommend upgrading to one of the fixed versions listed below. Fixed builds are available for supported YouTrack Server versions starting from 2024.2. If your installation is running an earlier version, we recommend upgrading to YouTrack Server 2024.2 or newer. 

We have found no evidence that any of these vulnerabilities were exploited outside of testing environments.

Please read on for the recommended actions.

Recommended action for YouTrack Server administrators

If you are running YouTrack Server, we strongly recommend upgrading to one of the following versions or newer:

2026.1.13757 for 2026.1 installations
2025.3.148033 for 2025.3 installations
2025.2.148048 for 2025.2 installations
2025.1.148120 for 2025.1 installations
2024.3.148430 for 2024.3 installations
2024.2.148429 for 2024.2 installations

If your installation is running a version earlier than 2024.2, we recommend upgrading to YouTrack Server 2024.2 or newer.

You can check your current version under Administration → Server Settings → Global Settings. To see which versions are available with your upgrade and support subscription, visit your JetBrains Account.

To upgrade your YouTrack version 2026.1, download the latest available version from the YouTrack download page, or choose a specific version on the previous versions page. For upgrade instructions, refer to the Installation and Upgrade documentation.

The vulnerabilities

In May 2026, independent researchers and the JetBrains team together identified several critical vulnerabilities via the Coordinated Disclosure Policy and internal security research activities.

As security research evolves through advances in automation and AI-assisted techniques, JetBrains continues to invest in vulnerability discovery, coordinated disclosure initiatives, and collaboration with the security community to help identify and address emerging risks.

Based on our internal investigation, the reports appear to have originated from advanced security research that leveraged AI-assisted testing techniques. The combination of extensive preparation, systematic analysis, and AI-assisted workflows likely enabled researchers to identify vulnerabilities in older areas of the codebase that had not been uncovered through previous security assessments.

The vulnerabilities affect YouTrack versions prior to the fixed releases listed above.

Two of the issues were relevant for YouTrack Cloud:

  • An admin account takeover was possible through authentication token forgery (CVE-2026-56141).
  • It was possible to bypass the email verification flow entirely (CVE-2026-56142).

YouTrack Server was affected by both issues listed above. In addition, an admin account takeover was possible via direct database access (CVE-2026-50242).

Mitigation

After receiving the reports, we patched YouTrack Cloud and prepared fixed builds for supported YouTrack Server versions starting from 2024.2.

We have found no evidence that any of the vulnerabilities were exploited outside of testing environments.

Security bulletin

A complete list of recently fixed security issues is available on the Fixed security issues page on the JetBrains website. You can also subscribe to receive email notifications about fixes in all JetBrains products.

Frequently asked questions

Which versions are affected?

The vulnerabilities affected YouTrack versions prior to the fixed releases listed in this post. Fixed Server builds are available for supported versions starting from 2024.2.

What should I do if my YouTrack Server version is older than 2024.2?

We recommend upgrading to YouTrack Server 2024.2 or newer.

Is YouTrack Cloud affected?

YouTrack Cloud was affected, but all Cloud instances have already been patched. We have found no evidence that any of the vulnerabilities were exploited outside of testing environments. No action is required from Cloud users.

Is YouTrack Server affected?

Yes. YouTrack Server is affected by all three vulnerabilities described in this post. Although we have found no evidence that any of the vulnerabilities were exploited outside of testing environments, we strongly recommend upgrading to a fixed version.

Was my data compromised?

We have found no evidence that any of the vulnerabilities were exploited outside of testing environments.

Support

If you have any questions regarding this issue, please get in touch with the YouTrack Support team.

Your YouTrack team

Subscribe to YouTrack Blog updates