CVE-2026-33392: High severity JetBrains YouTrack vulnerability
Published Apr 17, 2026
·Updated
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
Affected Software
2 affected components
JetBrains YouTrack<2025.3.131383
JetBrains YouTrack<2025.3.131383
Event History
Apr 17, 2026
CVE Published
via MITRE·07:46 AM
Data Sourced
via MITRE·07:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-33392?
CVE-2026-33392 is classified as a high severity vulnerability due to the ability of high privileged users to achieve remote code execution.
2
How do I fix CVE-2026-33392?
To address CVE-2026-33392, upgrade to JetBrains YouTrack version 2025.3.131384 or later.
3
What types of systems are affected by CVE-2026-33392?
CVE-2026-33392 affects JetBrains YouTrack versions prior to 2025.3.131383.
4
What does CVE-2026-33392 allow an attacker to do?
CVE-2026-33392 allows an attacker with high privileges to bypass sandbox restrictions and execute arbitrary code.
5
Is CVE-2026-33392 a known or zero-day vulnerability?
CVE-2026-33392 is a known vulnerability that has been publicly disclosed along with a fix.