Junglewise Threat Intelligence

CVE-2026-86505: JetBrains IntelliJ IDEA project metadata disclosure to marketplace

CVE-2026-86505 · Severity: low · CVSS 3.3 · Published 2026-09-07

Technologies: Jetbrains IntelliJ IDEA. Vendors: Jetbrains.

Executive brief

JetBrains IntelliJ IDEA is a code editor used by developers to write and manage software projects. A missing security check allowed project metadata to be sent to the JetBrains Marketplace without proper user consent, potentially exposing information about projects a developer was working on.

Technical details

The vulnerability is a missing project-trust validation in JetBrains IntelliJ IDEA before version 2026.2.2. When a project is opened, the IDE failed to properly verify the project's trust status before transmitting project metadata to the JetBrains Marketplace plugin service. This allows metadata leakage of locally stored project information to external services. The vulnerability requires a user to open a project in the affected IDE version; an attacker cannot directly trigger the leak remotely. JetBrains patched this issue in version 2026.2.2 by implementing proper project-trust checks before any marketplace communications.

Affected products

  • JetBrains IntelliJ IDEA before 2026.2.2

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Fixed in version 2026.2.2

References

Related threats