Junglewise Threat Intelligence

CVE-2026-64814: JetBrains IntelliJ IDEA unauthorized file access in Remote Development

CVE-2026-64814 · Severity: high · CVSS 8.6 · Published 2026-07-23

Technologies: Jetbrains IntelliJ IDEA. Vendors: Jetbrains.

Executive brief

JetBrains IntelliJ IDEA, a popular software development environment, contained a vulnerability in its Remote Development feature. This flaw allowed unauthorized individuals to access files on a remote system during a development session. An exploit could lead to the theft of sensitive source code, configuration files, or other proprietary data stored on the development server.

Technical details

A missing authorization vulnerability (CWE-862) exists in JetBrains IntelliJ IDEA's Remote Development component. The flaw allows a remote, unauthenticated attacker to access files within the context of a Remote Development session without proper validation. According to the CVSS vector, the attack is network-based, requires no special privileges or user interaction, and has a high impact on confidentiality with a scope change, suggesting access may extend beyond the immediate application environment. The issue is resolved in IntelliJ IDEA version 2026.2.

Affected products

  • JetBrains IntelliJ IDEA before 2026.2

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats