Impact
In JetBrains IntelliJ IDEA versions prior to 2026.2.2 the IJENT gRPC server was left without TLS protection or authentication. This defect permitted an attacker who can reach the gRPC endpoint to execute arbitrary code locally on the Remote Development host. The vulnerability represents a local code execution flaw and is classified under CWE‑306.
Affected Systems
The affected product is JetBrains IntelliJ IDEA. Versions before 2026.2.2 contain the flaw. No additional version pinning was supplied, so all earlier releases of IntelliJ IDEA that expose the IJENT gRPC server are at risk.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity and the lack of TLS means the attack can be carried out over an unencrypted channel. Although no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the missing authentication still provides a clear execution path. The attack vector is most likely local network access to the IJENT gRPC server, inferred from the description, but could be extended to external access if the server is exposed. The risk to integrity and confidentiality is significant, as arbitrary code could read or modify system files and potentially pivot to other systems.
OpenCVE Enrichment