Command Execution Vulnerability in JetBrains IntelliJ IDEA Affects Guest User Accounts
CVE-2026-49367

8HIGH

Key Information:

Vendor

Jetbrains

Vendor
CVE Published:
29 May 2026

What is CVE-2026-49367?

A vulnerability in JetBrains IntelliJ IDEA allows for command execution through the guest user account, affecting versions before 2026.1.1. This flaw could enable unauthorized users to execute malicious commands, potentially compromising system integrity. JetBrains has addressed this issue in the later version, emphasizing the importance of keeping software updated to mitigate security risks.

Affected Version(s)

IntelliJ IDEA 0 < 2026.1.1

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.