Junglewise Threat Intelligence

CVE-2026-49367: JetBrains IntelliJ IDEA command execution via guest account

CVE-2026-49367 · Severity: high · CVSS 8 · Published 2026-05-29

Technologies: Jetbrains IntelliJ IDEA. Vendors: Jetbrains.

Executive brief

A security vulnerability in JetBrains IntelliJ IDEA allowed unauthorized command execution through guest user accounts. IntelliJ IDEA is a widely used development environment for software engineering; an exploit could allow an attacker to run malicious code on a developer's machine, potentially leading to the theft of source code or full system compromise. This issue has been resolved in version 2026.1.1.

Technical details

A missing authorization vulnerability (CWE-862) in JetBrains IntelliJ IDEA versions prior to 2026.1.1 allowed for remote command execution. The flaw specifically resides in the handling of guest user accounts, where insufficient permission checks enabled the execution of arbitrary commands. The attack vector is network-based and requires low privileges (a guest account) and some user interaction. Successful exploitation grants the attacker the ability to execute code with the privileges of the application user, impacting confidentiality, integrity, and availability. The issue is addressed in IntelliJ IDEA 2026.1.1.

Affected products

  • JetBrains IntelliJ IDEA before 2026.1.1

Timeline

  • 2026-05-29: advisory: NVD publication date
  • 2026-05-29: disclosed: Initial disclosure by JetBrains

References

Related threats