Junglewise Threat Intelligence

CVE-2026-86501: JetBrains IntelliJ IDEA information disclosure in terminal logging

CVE-2026-86501 · Severity: low · CVSS 2.8 · Published 2026-09-07

Technologies: Jetbrains IntelliJ IDEA. Vendors: Jetbrains.

Executive brief

IntelliJ IDEA is a popular integrated development environment (IDE) used by software developers. A flaw in versions before 2026.2.2 caused terminal command input to be recorded in the application's debug log file, potentially exposing sensitive information such as passwords, API keys, or other credentials that a developer might have entered at the command line.

Technical details

The vulnerability is an information disclosure issue in IntelliJ IDEA's terminal logging mechanism. Terminal command input, including potentially sensitive data, was being written to the idea.log debug log file before version 2026.2.2. An attacker with local access to the affected machine or access to the log files could retrieve this information. The vulnerability requires local file system access and affects developers using the terminal feature within the IDE. A patch is available in version 2026.2.2 and later.

Affected products

  • JetBrains IntelliJ IDEA before 2026.2.2

Timeline

  • 2026-09-07: disclosed
  • 2026: patched: Fixed in version 2026.2.2

References

Related threats