CyberRota Analysis
AI-GeneratedJetBrains GoLand versions prior to 2026.2.2.1 have a vulnerability in the profiler's injected pprof server due to missing authentication, which can expose sensitive profiling data. This could lead to unauthorized access to performance metrics and insights about the application, potentially aiding attackers in exploiting other vulnerabilities. Organizations using affected versions of GoLand should prioritize patching to mitigate the risk of data exposure.
CVE
CVE-2026-86506
Severity
MEDIUM
CVSS
5.9
EPSS
0.24%
Original NVD Description
In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data