Client-Side Enforcement of Server-Side Security in IntelliJ IDEA - CVE-2026-64813
Published: August 17, 2026
Vulnerability details
The vulnerability allows a remote user to modify settings without authorization.
The vulnerability exists due to improper access control in Remote Development session settings handling when processing Remote Development session operations. A remote user can modify settings in a Remote Development session to modify settings without authorization.