Code Execution Vulnerability in JetBrains IntelliJ IDEA Affecting Local Development
CVE-2026-86502

8.4HIGH

Key Information:

Vendor

Jetbrains

Vendor
CVE Published:
7 September 2026

What is CVE-2026-86502?

A vulnerability in JetBrains IntelliJ IDEA up to version 2026.2.1 allows for potential local code execution due to inadequate TLS encryption and authentication on the IJent gRPC server. This oversight can be exploited on Remote Development hosts, posing a significant risk to user data and system integrity. It is imperative for users to upgrade to the latest version to mitigate potential threats and safeguard their development environments.

Affected Version(s)

IntelliJ IDEA 0 < 2026.2.2

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.