CVE-2026-86504: High severity JetBrains IntelliJ IDEA vulnerability
Published Sep 7, 2026
·Updated
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
Affected Software
1 affected component
JetBrains IntelliJ IDEA<2026.2.2
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Users of JetBrains IntelliJ IDEA versions before 2026.2.2 are exposed when building a Dev Container project whose trust has not been confirmed.
2
What does exploitation require?
An attacker needs to get a user to build a Dev Container project. The user must interact with the project, but no privileges are required before exploitation.
3
What is the impact of successful exploitation?
Successful exploitation can result in host-level code execution with high impact to confidentiality, integrity, and availability.
4
How can I remediate the issue?
Update JetBrains IntelliJ IDEA to version 2026.2.2 or later, which adds the missing project-trust confirmation before building a Dev Container.