CVE-2026-100256: High severity JetBrains IntelliJ IDEA vulnerability
Published Sep 30, 2026
·Updated
In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects
Affected Software
1 affected component
JetBrains IntelliJ IDEA<2026.2.3
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is most likely to be exposed to this issue?
Users of IntelliJ IDEA versions before 2026.2.3 who open or work with untrusted projects are the relevant exposure group.
2
What does an attacker need to exploit this vulnerability?
The listed attack vector is local, no privileges are required, and user interaction is required. Exploitation is associated with Structural Search script constraints in an untrusted project.