SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86504

HIGH · CVSS 7.8 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

JetBrains IntelliJ IDEA versions prior to 2026.2.2 are vulnerable due to a lack of project-trust confirmation before building a Dev Container, which could allow an attacker to execute arbitrary code at the host level. This high-severity vulnerability poses significant risks for developers and organizations using IntelliJ IDEA, particularly those that work with untrusted code or third-party projects. Users of affected versions should prioritize applying the latest updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86504
Severity
HIGH
CVSS
7.8
EPSS
0.13%

Original NVD Description

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution