CVE-2026-64809: High severity JetBrains PhpStorm vulnerability
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains PhpStormto a version that resolves this vulnerability.Fixed in 2026.2 - Configuration
Ensure project trust is granted before granting/using the configured interpreter for the project to prevent arbitrary code execution prior to 2026.2.
JetBrains PhpStorm Project trust via configured interpreter = Not applicable (ensure trust is granted before using the interpreter)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64809?
The severity of CVE-2026-64809 is rated as high with a score of 8.4.
How do I fix CVE-2026-64809?
To mitigate CVE-2026-64809, update your JetBrains PhpStorm to version 2026.2 or later.
What type of vulnerability is CVE-2026-64809?
CVE-2026-64809 is classified as an arbitrary code execution vulnerability.
What software is affected by CVE-2026-64809?
CVE-2026-64809 affects JetBrains PhpStorm versions prior to 2026.2.
What impact does CVE-2026-64809 have?
CVE-2026-64809 can allow attackers to execute arbitrary code before project trust is established.