CVE-2026-64815: Code Injection
Published Jul 23, 2026
·Updated
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
Affected Software
2 affected components
JetBrains IntelliJ IDEA<2026.2
JetBrains IntelliJ IDEA<2026.2
Event History
Jul 23, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-64815?
CVE-2026-64815 has a severity score of 8.1, categorized as high.
2
What does CVE-2026-64815 exploit?
CVE-2026-64815 allows arbitrary code injection via UI Designer form files in JetBrains IntelliJ IDEA.
3
How can I fix CVE-2026-64815?
To fix CVE-2026-64815, upgrade to JetBrains IntelliJ IDEA version 2026.2 or higher.
4
What is the risk level of CVE-2026-64815?
CVE-2026-64815 is classified with a risk level of 75.
5
Which software is affected by CVE-2026-64815?
CVE-2026-64815 affects JetBrains IntelliJ IDEA versions prior to 2026.2.