CVE-2026-86505: Low severity JetBrains IntelliJ IDEA vulnerability
Published Sep 7, 2026
·Updated
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace
Affected Software
1 affected component
JetBrains IntelliJ IDEA<2026.2.2
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and interaction are required for exploitation?
The attack vector is local and user interaction is required. No privileges are required according to the CVSS vector.
2
What information could be exposed?
The issue could leak project metadata to JetBrains Marketplace. The provided information does not identify the specific metadata fields involved.
3
Which IntelliJ IDEA versions should be remediated?
JetBrains IntelliJ IDEA versions before 2026.2.2 are affected. Update to version 2026.2.2 or later.