Impact
In JetBrains PyCharm versions before 2026.2.1, a missing authentication flaw in the Jupyter MCP tools allows an attacker to execute arbitrary code. The weakness, classified as CWE‑306, can be triggered through the exposed tools and results in full control over the host system running PyCharm. No additional privileges are required once the tool is accessed, making the impact immediate and severe.
Affected Systems
The vulnerability affects JetBrains PyCharm installations older than 2026.2.1. All users running those releases are susceptible, regardless of operating system.
Risk and Exploitability
The CVSS score of 8.4 signals high severity. The EPSS score is not available, so the current exploitation probability is unclear, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the Jupyter MCP interface, which could be reachable locally or remotely depending on the user’s environment. Once accessed without authentication, the flaw permits arbitrary code execution on the host.
OpenCVE Enrichment