CVE-2026-41882: High severity JetBrains IntelliJ IDEA vulnerability
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41882?
CVE-2026-41882 is classified as a high-severity vulnerability due to its potential for unauthorized access to local files.
How do I fix CVE-2026-41882?
To mitigate CVE-2026-41882, update JetBrains IntelliJ IDEA to a version greater than 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, or 2026.1.1.
What types of local files can be accessed due to CVE-2026-41882?
CVE-2026-41882 allows attackers to read arbitrary local files on the system where the affected version of JetBrains IntelliJ IDEA is running.
Is remote code execution possible with CVE-2026-41882?
CVE-2026-41882 does not lead to remote code execution, but it does allow for unauthorized file access which can be exploited.
What versions of JetBrains IntelliJ IDEA are affected by CVE-2026-41882?
CVE-2026-41882 affects versions prior to 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, and 2026.1.1.