Impact
The vulnerability enables a remote developer to read arbitrary files on the host system during a Remote Development session in JetBrains IntelliJ IDEA versions prior to 2026.2, because the application lacks proper authorization checks when servicing file requests. An attacker can therefore obtain sensitive configuration files, credentials or source code that is not intended for the client, leading to confidentiality violations.
Affected Systems
JetBrains IntelliJ IDEA installations running any release earlier than the 2026.2 update are affected. Versions 2026.2 and later include the fix, so systems on those releases are not vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 8.6, classifying it as high severity, while the EPSS score of less than 1% suggests that exploitation in the wild is currently unlikely; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker who already has an active Remote Development session with a JetBrains IntelliJ IDEA instance and can issue file retrieval requests, exploiting the missing authorization checks to read files outside the intended project scope.
OpenCVE Enrichment