CVE-2026-86504CWE-829

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

High · published September 7, 2026

CVSS v3.1
7.8
EPSS
In the wild
Unconfirmed
What it is

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
Not scored
Weakness
CWE-829 · Inclusion of Functionality from Untrusted Control Sphere
Published
2026-09-07T16:26Z
Timeline
  • 07 SEP 16:26Z
    In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
    cvelistv5