Description
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace
Published: 2026-09-07
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains IntelliJ IDEA before version 2026.2.2 lacked a required project-trust check, allowing the IDE to expose sensitive project metadata to the JetBrains Marketplace. The missing check permits the leakage of structural and descriptive data about a project, potentially revealing its organization, coding patterns, and tool configuration. While the vulnerability does not grant code execution or privilege escalation, it compromises confidentiality by allowing external parties to obtain information that could be used for targeted attacks or competitive intelligence.

Affected Systems

Any installation of JetBrains IntelliJ IDEA with a version earlier than 2026.2.2 is susceptible. The issue affects all users who open or import projects that trigger the project-trust mechanism, without restriction to specific editions or deployment environments.

Risk and Exploitability

The CVSS score of 3.3 indicates a low severity risk, and the EPSS score is not available, which further suggests limited exploitation probability. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector is local or remote use of the IDE when importing a project; an attacker would need access to the IDE environment or the ability to supply a specially crafted project to influence what metadata is exposed. The impact is limited to information disclosure and does not affect integrity or availability.

Generated by OpenCVE AI on September 7, 2026 at 17:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest IntelliJ IDEA release (2026.2.2 or newer) that includes the missing project-trust check.
  • Confirm that the project-trust feature is active in the IDE settings to prevent inadvertent metadata exposure.
  • Validate that no unauthorized or unverified projects are imported from external sources, and monitor the JetBrains Marketplace for any unusual data distribution patterns.

Generated by OpenCVE AI on September 7, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Missing Project-Trust Check in JetBrains IntelliJ IDEA Leaks Project Metadata
First Time appeared Jetbrains
Jetbrains intellij Idea
Vendors & Products Jetbrains
Jetbrains intellij Idea

Mon, 07 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Jetbrains Intellij Idea
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-09-07T16:26:50.762Z

Reserved: 2026-09-07T16:13:41.489Z

Link: CVE-2026-86505

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T17:17:29.020

Modified: 2026-09-07T17:17:29.020

Link: CVE-2026-86505

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T17:45:17Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data