CVE-2026-86506: Medium severity JetBrains GoLand vulnerability
Published Sep 7, 2026
·Updated
In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data
Affected Software
1 affected component
JetBrains GoLand<2026.2.2.1
Event History
Sep 7, 2026
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
JetBrains GoLand installations before 2026.2.2.1 are affected when the GoLand profiler's injected pprof server is present. The exposed information is profiling data.
2
Does exploitation require an authenticated account or user interaction?
No. The reported vector is network-based, requires no privileges, and requires no user interaction; however, the attack complexity is rated high.
3
What security impact is reported?
The issue can expose profiling data, with high confidentiality impact. No integrity or availability impact is reported.