CVSS 10.0CVSS 10.0 · CRITICAL
CVE-2026-64812
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
View on NVDAnalysis
Esta vulnerabilidad en JetBrains IntelliJ IDEA permite la inyección de comandos no autorizada durante sesiones de Remote Development. Un atacante puede manipular el entorno de desarrollo sin necesidad de autenticación previa, comprometiendo la integridad del código y la infraestructura conectada. Es fundamental actualizar a la versión 2026.2 para mitigar este riesgo de severidad máxima.
Relevant roles
JavaBackendPythonCyberSecurity
Severity
Score: 10.0(CRITICAL)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE):
CWE-306EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session
Published: 7/23/2026, 12:18:36 PM
Last modified: 7/23/2026, 2:35:20 PM