Impact
The flaw permits an attacker with access to a JetBrains IntelliJ IDEA Remote Development session to modify IDE settings without authorization. This can lead to changes in configuration files or environment variables that may facilitate further attacks or disrupt development workflows. The weakness is categorized as CWE-602, indicating improper restriction of operations within a resource.
Affected Systems
JetBrains IntelliJ IDEA versions earlier than 2026.2 when the Remote Development feature is enabled. Only installations that support remote collaboration are impacted; other JetBrains IDEs are not listed as affected.
Risk and Exploitability
The issue has a CVSS score of 10, marking it as critical. An EPSS score of less than 1% suggests that it is not widely exploited, and it is not listed in CISA's KEV catalog. Attackers can exploit the vulnerability remotely by connecting to a Remote Development session and issuing privileged commands that alter IDE settings, potentially creating a foothold for further lateral movement or system compromise.
OpenCVE Enrichment