SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-86506

MEDIUM · CVSS 5.9 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-07 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

JetBrains GoLand versions prior to 2026.2.2.1 have a vulnerability in the profiler's injected pprof server due to missing authentication, which can expose sensitive profiling data. This could lead to unauthorized access to performance metrics and insights about the application, potentially aiding attackers in exploiting other vulnerabilities. Organizations using affected versions of GoLand should prioritize patching to mitigate the risk of data exposure.

CVE
CVE-2026-86506
Severity
MEDIUM
CVSS
5.9
EPSS
0.24%

Original NVD Description

In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data