VULNERABILITY OVERVIEW
A path traversal vulnerability in IntelliJ IDEA's project workspace ID handling allows remote code execution; the scope-changed CVSS vector (S:C) reflects that a malicious repository or project file could trigger execution on an unsuspecting developer's machine when opened. Published July 10, 2026, as part of a JetBrains advisory batch that also disclosed file access and XSS issues in TeamCity (CVE-2026-59793/CVE-2026-59794) and YouTrack (CVE-2026-59791/CVE-2026-61492). No public exploit or in-the-wild exploitation has been observed; patch to 2026.1.4 or upgrade to the 2026.2 branch.
CVSS BREAKDOWN
↗
Attack Vector
NETWORK
△
Attack Complexity
LOW
⚷
Privs Required
NONE
◈
User Interaction
REQUIRED
⊕
Scope / Impact
CHANGED
C:H · I:H · A:L
AFFECTED VERSIONS
IntelliJ IDEA prior to 2026.1.4 and prior to 2026.2CITATIONS
- → https://nvd.nist.gov/vuln/detail/CVE-2026-59792
- → https://www.jetbrains.com/privacy-security/issues-fixed/
- → https://cve.threatint.eu/CVE/CVE-2026-59792