Skip to content
CVSS 7.4 · HIGH

CVE-2026-41882

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

View on NVD

Analysis

JetBrains IntelliJ IDEA has a vulnerability in its built-in web server that allows an attacker to read arbitrary files from the local filesystem. Anyone using versions prior to the 2024.3, 2025.1, 2025.2, 2025.3, or 2026.1 patch releases should update immediately to protect sensitive data like private keys and configuration files.

Severity

Score: 7.4(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: REQUIRED
S: CHANGED
C: HIGH
I: NONE
A: NONE
Weakness (CWE): CWE-59

EPSS

Probability of exploitation (next 30 days): 0.0000 (0.0%)
Percentile: 0.0%
EPSS: 2026-05-06

Affects

jetbrains:intellij_idea

Technical description

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

Published: 4/30/2026, 12:16:24 PM
Last modified: 5/5/2026, 12:24:51 AM

References

HomeEventsBlogResourcesTeam