CVE-2026-33392
7.2JetBrains · YouTrack
A sandbox bypass vulnerability in JetBrains YouTrack allows a high-privileged user to achieve remote code execution.
Executive summary
A critical sandbox bypass vulnerability in JetBrains YouTrack allows authenticated high-privileged users to achieve remote code execution on the underlying server.
Vulnerability
The vulnerability is identified as a sandbox bypass (CWE-1336) that permits an authenticated user with high privileges to escape the restricted environment and execute arbitrary code on the host system.
Business impact
The ability for an attacker to achieve remote code execution poses a severe risk to organizational data integrity and system availability. Given the CVSS score of 7.2, this vulnerability could lead to total system compromise, unauthorized data exfiltration, or the deployment of persistent threats within the internal network.
Remediation
Immediate Action: Administrators must update JetBrains YouTrack to version 2025.3.131383 or later to apply the necessary security patches.
Proactive Monitoring: Security teams should review application and system logs for unauthorized configuration changes or unexpected process execution spawned by the YouTrack service account.
Compensating Controls: Restrict administrative access to the YouTrack instance to a limited set of trusted personnel and ensure the application is running within a containerized environment with hardened resource restrictions.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
Due to the potential for full system compromise, this vulnerability represents a significant security risk to the environment. Organizations utilizing JetBrains YouTrack should prioritize the installation of the vendor-provided update immediately to eliminate the sandbox bypass vector and prevent unauthorized code execution.