Description
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
Published: 2026-07-23
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability enables a remote developer to read arbitrary files on the host system during a Remote Development session in JetBrains IntelliJ IDEA versions prior to 2026.2, because the application lacks proper authorization checks when servicing file requests. An attacker can therefore obtain sensitive configuration files, credentials or source code that is not intended for the client, leading to confidentiality violations.

Affected Systems

JetBrains IntelliJ IDEA installations running any release earlier than the 2026.2 update are affected. Versions 2026.2 and later include the fix, so systems on those releases are not vulnerable.

Risk and Exploitability

The flaw carries a CVSS score of 8.6, classifying it as high severity, while the EPSS score of less than 1% suggests that exploitation in the wild is currently unlikely; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker who already has an active Remote Development session with a JetBrains IntelliJ IDEA instance and can issue file retrieval requests, exploiting the missing authorization checks to read files outside the intended project scope.

Generated by OpenCVE AI on August 3, 2026 at 21:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains IntelliJ IDEA to version 2026.2 or later to apply the fixed authorization controls.
  • Restrict Remote Development access to trusted users or networks, enforcing VPN or firewall rules to limit potential attackers.
  • Configure project file scope settings to ensure only intended project files are accessible until the patch is installed.

Generated by OpenCVE AI on August 3, 2026 at 21:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthorized File Access in JetBrains IntelliJ IDEA Remote Development Sessions before 2026.2

Sun, 02 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthorized File Access in JetBrains IntelliJ IDEA Remote Development Sessions before 2026.2

Sat, 01 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unauthorized File Access in Remote Development Sessions of JetBrains IntelliJ IDEA

Mon, 27 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unauthorized File Access in Remote Development Sessions of JetBrains IntelliJ IDEA

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains intellij Idea
Vendors & Products Jetbrains
Jetbrains intellij Idea

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Description In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Jetbrains Intellij Idea
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-23T13:21:25.814Z

Reserved: 2026-07-20T18:20:30.920Z

Link: CVE-2026-64814

cve-icon Vulnrichment

Updated: 2026-07-23T13:21:21.541Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T12:18:37.010

Modified: 2026-07-28T17:10:52.127

Link: CVE-2026-64814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:45:03Z

Weaknesses