SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64810

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

JetBrains IntelliJ IDEA versions prior to 2026.2 are vulnerable to HTML injection in IDE notifications, which could enable attackers to silently track user activities. This vulnerability poses a medium risk, particularly for organizations that rely on IntelliJ IDEA for software development and need to safeguard user privacy and data integrity. Users and administrators of affected versions should prioritize applying updates to mitigate potential exploitation.

CVE
CVE-2026-64810
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%

Original NVD Description

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking

Related CVEs

Other vulnerabilities affecting the same vendor(s)