SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-86503

LOW · CVSS 3.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

JetBrains IntelliJ IDEA versions prior to 2026.2.2 are vulnerable to Server-Side Request Forgery (SSRF) when opening untrusted projects that utilize Kubernetes spec-source URLs. This vulnerability could allow an attacker to manipulate requests sent from the server, potentially exposing sensitive information or internal services. Organizations using affected versions of IntelliJ IDEA, particularly those leveraging Kubernetes, should prioritize updating to mitigate this risk.

CVE
CVE-2026-86503
Severity
LOW
CVSS
3.3
EPSS
0.10%
Kubernetes

Original NVD Description

In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching