Description
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
Published: 2026-07-23
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to execute arbitrary code within the IntelliJ IDEA process before the project is granted trust through the development container configuration. This weakness is classified as CWE‑829, indicating an improper restriction of operations within the bounds of a resource. An attacker who can influence the development container configuration could run code with the same privileges as the IDE, potentially leading to full compromise of the host system.

Affected Systems

JetBrains IntelliJ IDEA versions released before 2026.2 are affected. All earlier releases, including 2025.x and prior, are susceptible to the described exploitation path.

Risk and Exploitability

The CVSS score of 7.8 marks this as a high‑severity flaw, while the EPSS score of less than 1% indicates a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector appears to be local or requires an attacker to influence the IDE’s configuration; direct remote exploitation is not documented.

Generated by OpenCVE AI on August 4, 2026 at 15:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to IntelliJ IDEA 2026.2 or later to apply the vendor‑provided fix.
  • If an upgrade is not immediately possible, disable or remove the development container configuration until the patch is applied to prevent pre‑trust code execution.
  • Continuously monitor JetBrains security advisories for additional mitigation steps or updates.

Generated by OpenCVE AI on August 4, 2026 at 15:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Untrusted Development Container Configuration in IntelliJ IDEA

Sun, 02 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Untrusted Development Container Configuration in IntelliJ IDEA

Sat, 01 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Development Container Configuration in IntelliJ IDEA Prior to 2026.2

Mon, 27 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Development Container Configuration in IntelliJ IDEA Prior to 2026.2

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains intellij Idea
Vendors & Products Jetbrains
Jetbrains intellij Idea

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Jetbrains Intellij Idea
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-24T03:56:15.755Z

Reserved: 2026-07-20T18:20:30.270Z

Link: CVE-2026-64811

cve-icon Vulnrichment

Updated: 2026-07-23T13:25:40.908Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T12:18:36.663

Modified: 2026-07-28T17:09:51.890

Link: CVE-2026-64811

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere