Executive brief
A critical vulnerability was identified in JetBrains IntelliJ IDEA's Remote Development feature, which allows developers to code on remote servers. An unauthorized attacker could remotely modify application settings without any prior authentication. This could lead to a complete compromise of the development environment, potentially allowing for data theft or the execution of malicious code.
Technical details
A vulnerability classified as CWE-602 (Client-Side Enforcement of Server-Side Security) exists in JetBrains IntelliJ IDEA before version 2026.2. The flaw allows an unauthenticated remote attacker to modify settings during a Remote Development session. Because the CVSS vector indicates a scope change (S:C) and high impact across confidentiality, integrity, and availability, this suggests that the settings modification can be leveraged to gain broader control over the host or the development environment. The issue is resolved in version 2026.2.
Affected products
- JetBrains IntelliJ IDEA before 2026.2
Timeline
- 2026-07-23: advisory: NVD publication date
- 2026-07-23: patched: Fix available in version 2026.2