Junglewise Threat Intelligence

CVE-2026-64812: JetBrains IntelliJ IDEA unauthorized input injection in Remote Development session

CVE-2026-64812 · Severity: critical · CVSS 10 · Published 2026-07-23

Technologies: Jetbrains IntelliJ IDEA. Vendors: Jetbrains.

Executive brief

IntelliJ IDEA is a popular development environment used by software engineers to write and manage code. A critical vulnerability in its Remote Development feature allows unauthorized individuals to inject commands or input into active sessions. This could lead to a total compromise of the development environment, including the theft of source code or the execution of malicious software on the developer's machine.

Technical details

A vulnerability classified as CWE-306 (Missing Authentication for Critical Function) exists in JetBrains IntelliJ IDEA's Remote Development component. The flaw allows an unauthenticated remote attacker to inject input into a session without authorization. Due to the 'Scope: Changed' (S:C) metric in the CVSS score, this injection can likely escape the immediate session context to impact the underlying host or integrated services. The vulnerability is fixed in version 2026.2.

Affected products

  • JetBrains IntelliJ IDEA before 2026.2

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats