Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ |
|
Mon, 07 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing Project Trust Confirmation Allows Host‑Level Code Execution in JetBrains IntelliJ IDEA Dev Containers | |
| First Time appeared |
Jetbrains
Jetbrains intellij Idea |
|
| Vendors & Products |
Jetbrains
Jetbrains intellij Idea |
Mon, 07 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution | |
| Weaknesses | CWE-829 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: JetBrains
Published:
Updated: 2026-09-07T16:26:50.440Z
Reserved: 2026-09-07T16:13:41.211Z
Link: CVE-2026-86504
No data.
Status : Received
Published: 2026-09-07T17:17:28.903
Modified: 2026-09-07T17:17:28.903
Link: CVE-2026-86504
No data.
OpenCVE Enrichment
Updated: 2026-09-07T17:45:17Z
-
CWE-829
Inclusion of Functionality from Untrusted Control Sphere