Host-level Code Execution Vulnerability in JetBrains IntelliJ IDEA
CVE-2026-86504
7.8HIGH
What is CVE-2026-86504?
In JetBrains IntelliJ IDEA versions prior to 2026.2.2, a vulnerability exists that enables host-level code execution due to the absence of project-trust confirmation before building a Dev Container. This oversight can allow malicious code to execute on the host system, posing significant risks to security. Users are urged to update to the latest version to mitigate this risk.
Affected Version(s)
IntelliJ IDEA 0 < 2026.2.2