Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4212 articles · 221931 vulns · 36/41 feeds (7d)
← Back to list
8.4
CVE-2026-86502PATCHED
jetbrains · intellij idea

CVE-2026-86502: In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code ex

Description

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts

Affected Products

VendorProductVersions
jetbrainsintellij idea0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
jetbrainsintellij ideacert_advisory90%

References

  • https://www.jetbrains.com/privacy-security/issues-fixed/

Related News (2 articles)

Tier B
BSI Advisories16d ago
[NEU] [hoch] JetBrains IntelliJ IDEA: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB16d ago
CVE-2026-86502 | JetBrains IntelliJ IDEA up to 2026.2.1 IJent gRPC Server improper authentication
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.4 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
2026.2.2
CWECWE-306
PublishedSep 7, 2026
Trending Score7
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-63077EXPKEV
CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
Trending: 168
CRITICALCVE-2026-86478
CVE-2026-86478: In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthent
Trending: 10
CRITICALCVE-2026-86480
CVE-2026-86480: In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser pri
Trending: 7
HIGHCVE-2026-86479
CVE-2026-86479: In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restric
Trending: 7
HIGHCVE-2026-86482
CVE-2026-86482: In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation
Trending: 7

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 7, 2026
Discovered by ZDM
Sep 7, 2026
Patch Available
Sep 9, 2026