Executive brief
JetBrains IntelliJ IDEA, a popular software development environment, contained a vulnerability in its Remote Development feature. This flaw allowed unauthorized individuals to access files on a remote system during a development session. An exploit could lead to the theft of sensitive source code, configuration files, or other proprietary data stored on the development server.
Technical details
A missing authorization vulnerability (CWE-862) exists in JetBrains IntelliJ IDEA's Remote Development component. The flaw allows a remote, unauthenticated attacker to access files within the context of a Remote Development session without proper validation. According to the CVSS vector, the attack is network-based, requires no special privileges or user interaction, and has a high impact on confidentiality with a scope change, suggesting access may extend beyond the immediate application environment. The issue is resolved in IntelliJ IDEA version 2026.2.
Affected products
- JetBrains IntelliJ IDEA before 2026.2
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory