CVE-2026-64810: XSS
Published Jul 23, 2026
·Updated
In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking
Affected Software
2 affected components
JetBrains IntelliJ IDEA<2026.2
JetBrains IntelliJ IDEA<2026.2
Event History
Jul 23, 2026
CVE Published
via MITRE·11:36 AM
Data Sourced
via MITRE·11:36 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-64810?
The severity of CVE-2026-64810 is medium, with a score of 4.3.
2
How do I fix CVE-2026-64810?
To fix CVE-2026-64810, update JetBrains IntelliJ IDEA to version 2026.2 or later.
3
What kind of attack does CVE-2026-64810 allow?
CVE-2026-64810 allows for HTML injection in IDE notifications, which can facilitate silent user activity tracking.
4
Which software is affected by CVE-2026-64810?
CVE-2026-64810 affects JetBrains IntelliJ IDEA before version 2026.2.
5
What mitigation strategies exist for CVE-2026-64810?
Mitigation for CVE-2026-64810 involves updating to the latest version of JetBrains IntelliJ IDEA to avoid the vulnerability.