Impact
The vulnerability causes JetBrains GoLand to record sensitive configuration details, such as authentication credentials or API keys, to log files by default. This results in the exposure of confidential data to any actor who can read the logs. The weakness corresponds to CWE‑532, indicating log file sensitive information is improperly protected.
Affected Systems
JetBrains GoLand installations prior to version 2026.2. The advisory does not specify which operating systems are affected; therefore, any system on which GoLand runs without an upgrade may contain the flaw.
Risk and Exploitability
The CVSS score of 3.5 denotes a low confidentiality impact and simple attack complexity. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting exploitation is unlikely. The likely attack vector is local file access or misconfigured log directory permissions; this is inferred from the description, as the advisory does not explicitly identify the vector.
OpenCVE Enrichment