CVE-2026-86504CWE-829
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
High · published September 7, 2026
What it is
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
The record
Technical detail
- CVSS v3.1
- 7.8 · HIGH
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- Not scored
- Weakness
- CWE-829 · Inclusion of Functionality from Untrusted Control Sphere
- Published
- 2026-09-07T16:26Z
Timeline