Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-64812

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

View on NVD

Analysis

Esta vulnerabilidad en JetBrains IntelliJ IDEA permite la inyección de comandos no autorizada durante sesiones de Remote Development. Un atacante puede manipular el entorno de desarrollo sin necesidad de autenticación previa, comprometiendo la integridad del código y la infraestructura conectada. Es fundamental actualizar a la versión 2026.2 para mitigar este riesgo de severidad máxima.

Relevant roles

JavaBackendPythonCyberSecurity

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-306

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Published: 7/23/2026, 12:18:36 PM
Last modified: 7/23/2026, 2:35:20 PM

References

HomeEventsBlogResourcesTeam