In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
📦
intellij_idea
Vendor: jetbrains
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
9
Remote Access
Total CVEs
78
Total Indexed
Avg. EPSS
0.74%
Exploit Prob.
Security Vulnerability Index
Page 1 / 8
9.6
CVSS
Severity: CRITICAL
3.3
CVSS
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
Severity: LOW
4.5
CVSS
In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
Severity: MEDIUM
8.0
CVSS
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
Severity: HIGH
7.8
CVSS
CVE-2026-49366
RCE
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
Severity: HIGH
0.0
CVSS