Remote Code Execution Vulnerability in JetBrains IntelliJ IDEA
CVE-2026-100256

7.8HIGH

Key Information:

Vendor

Jetbrains

Vendor
CVE Published:
30 September 2026

What is CVE-2026-100256?

A vulnerability in JetBrains IntelliJ IDEA allows for remote code execution through Structural Search script constraints in untrusted projects. This flaw enables attackers to execute arbitrary code, potentially compromising the integrity and security of user systems. Users are advised to update their software to the latest version to mitigate risk.

Affected Version(s)

IntelliJ IDEA 0 < 2026.2.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.