Impact
JetBrains IntelliJ IDEA, in all releases prior to version 2026.2, contains an unauthorized input injection vulnerability that can be exercised during a Remote Development session. The flaw allows an attacker to inject arbitrary input into the IDE environment; the secondary impact, such as code execution, is not explicitly confirmed in the advisory, but the injection could be used to tamper with files or settings, potentially compromising confidentiality, integrity, or availability. The weakness is categorized as CWE‑306, indicating a missing authentication check for sensitive functions.
Affected Systems
Every edition of IntelliJ IDEA developed by JetBrains that predates release 2026.2 is affected. No finer‑grained version data is provided beyond this cut‑off.
Risk and Exploitability
The CVSS score of 10 marks this vulnerability as critical, whereas the EPSS score of less than 1 % indicates a very low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation likely requires an established Remote Development session, which usually needs prior authentication; the missing authentication check then allows the injection once the session is active.
OpenCVE Enrichment