Description
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
Published: 2026-07-23
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw permits an attacker with access to a JetBrains IntelliJ IDEA Remote Development session to modify IDE settings without authorization. This can lead to changes in configuration files or environment variables that may facilitate further attacks or disrupt development workflows. The weakness is categorized as CWE-602, indicating improper restriction of operations within a resource.

Affected Systems

JetBrains IntelliJ IDEA versions earlier than 2026.2 when the Remote Development feature is enabled. Only installations that support remote collaboration are impacted; other JetBrains IDEs are not listed as affected.

Risk and Exploitability

The issue has a CVSS score of 10, marking it as critical. An EPSS score of less than 1% suggests that it is not widely exploited, and it is not listed in CISA's KEV catalog. Attackers can exploit the vulnerability remotely by connecting to a Remote Development session and issuing privileged commands that alter IDE settings, potentially creating a foothold for further lateral movement or system compromise.

Generated by OpenCVE AI on August 3, 2026 at 21:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade IntelliJ IDEA to version 2026.2 or later, incorporating the fix for the unauthorized settings modification issue.
  • Disable or limit the Remote Development feature, ensuring it is only enabled for trusted users and that access control checks are enforced before allowing settings changes, thereby addressing the CWE-602 weakness.
  • Restrict Remote Development connections by configuring network firewalls or VPNs to allow access only from trusted networks, thereby reducing the exposure of the feature to potential attackers.

Generated by OpenCVE AI on August 3, 2026 at 21:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Settings Modification via Remote Development Session

Thu, 30 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Settings Modification via Remote Development Session

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains intellij Idea
Vendors & Products Jetbrains
Jetbrains intellij Idea

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
Weaknesses CWE-602
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Jetbrains Intellij Idea
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-24T03:56:17.355Z

Reserved: 2026-07-20T18:20:30.707Z

Link: CVE-2026-64813

cve-icon Vulnrichment

Updated: 2026-07-23T13:20:46.103Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T12:18:36.897

Modified: 2026-07-28T17:10:41.343

Link: CVE-2026-64813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:45:03Z

Weaknesses
  • CWE-602

    Client-Side Enforcement of Server-Side Security