CVE-2026-86503: SSRF
Published Sep 7, 2026
·Updated
In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching
Affected Software
1 affected component
JetBrains IntelliJ IDEA<2026.2.2
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Users of JetBrains IntelliJ IDEA versions before 2026.2.2 are exposed when they open an untrusted project.
2
What must happen for exploitation to occur?
A user must open an untrusted project. The issue involves Kubernetes spec-source URL fetching, which can trigger server-side request forgery.
3
Is this remotely exploitable without user interaction?
No. The supplied vector indicates local attack access and required user interaction; the user must open the project.