BRIEFING NOTE: CVE-2026-33392 JetBrains YouTrack versions prior to 2025.3.131383 contain a sandbox bypass vulnerability that allows high-privileged users to achieve Remote Code Execution (RCE). This vulnerability affects administrative or elevated-privilege accounts within the YouTrack issue tracking platform. The vulnerability carries a CVSS score of 7.2 (HIGH) with a network-based attack vector requiring no user interaction. Attack complexity is low, indicating the vulnerability can be exploited reliably once a high-privileged account is compromised. Successful exploitation results in complete system compromise with high impact to confidentiality, integrity, and availability. Current exploitation appears minimal with an extremely low EPSS score of 0.000010, indicating this vulnerability ranks lower than 99.98% of all known CVEs in terms of active exploitation probability. The vulnerability is not present on the CISA Known Exploited Vulnerabilities list and shows no community attention on the Hot List. Immediate patching is recommended for organizations running affected YouTrack versions, particularly those with strict access controls over privileged accounts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 2025.3.131383CPE match | cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*:* | ||
< 2025.3.131383CPE matchmatch criteria | cpe:2.3:a:jetbrains:youtrack:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.