Jetbrains
Jetbrains Intellij Idea: vulnerabilidades y CVE
Jetbrains Intellij Idea tiene 82 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 11 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE82
Últimos 12 meses26
Críticas11
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100256 | Alta (7.8) | 0.13% | — | 30 sept 2026 | In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects |
| CVE-2026-86505 | Baja (3.3) | 0.15% | — | 7 sept 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace |
| CVE-2026-86504 | Alta (7.8) | 0.18% | — | 7 sept 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution |
| CVE-2026-86503 | Baja (3.3) | 0.14% | — | 7 sept 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching |
| CVE-2026-86502 | Alta (8.4) | 0.21% | — | 7 sept 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts |
| CVE-2026-86501 | Baja (2.8) | 0.39% | — | 7 sept 2026 | In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log |
| CVE-2026-75058 | Media (5.5) | 0.15% | — | 17 ago 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers |
| CVE-2026-75057 | Media (6.2) | 0.17% | — | 17 ago 2026 | In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log |
| CVE-2026-75056 | Alta (7.8) | 0.19% | — | 17 ago 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible |
| CVE-2026-75055 | Media (5.5) | 0.15% | — | 17 ago 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE |
| CVE-2026-75054 | Media (6.3) | 0.15% | — | 17 ago 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects |
| CVE-2026-75053 | Media (5.4) | 0.24% | — | 17 ago 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint |
| CVE-2026-75052 | Media (4.4) | 0.18% | — | 17 ago 2026 | In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects |
| CVE-2026-64815 | Crítica (9.8) | 0.48% | — | 23 jul 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files |
| CVE-2026-64814 | Alta (8.6) | 0.39% | — | 23 jul 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session |
| CVE-2026-64813 | Crítica (10) | 0.52% | — | 23 jul 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session |
| CVE-2026-64812 | Crítica (10) | 0.48% | — | 23 jul 2026 | In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session |
| CVE-2026-64811 | Alta (7.8) | 0.18% | — | 23 jul 2026 | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration |
| CVE-2026-64810 | Media (6.1) | 0.25% | — | 23 jul 2026 | In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking |
| CVE-2026-59792 | Crítica (9.8) | 0.60% | — | 10 jul 2026 | In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible |
| CVE-2026-49383 | Baja (3.3) | 0.14% | — | 29 may 2026 | In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible |
| CVE-2026-49382 | Alta (7.8) | 0.18% | — | 29 may 2026 | In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin |
| CVE-2026-49367 | Alta (8.8) | 0.51% | — | 29 may 2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account |
| CVE-2026-49366 | Alta (7.8) | 0.68% | — | 29 may 2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion |
| CVE-2026-41882 | Alta (7.5) | 0.44% | — | 30 abr 2026 | In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server |
| CVE-2025-68269 | Media (5.4) | 0.11% | — | 16 dic 2025 | In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH |
| CVE-2025-57730 | Media (4.6) | 0.43% | — | 20 ago 2025 | In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature |
| CVE-2025-57729 | Alta (7.3) | 0.13% | — | 20 ago 2025 | In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start |
| CVE-2025-57728 | Media (6.5) | 0.25% | — | 20 ago 2025 | In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files |
| CVE-2025-57727 | Alta (7.5) | 0.20% | — | 20 ago 2025 | In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.