Inclusion of Functionality from Untrusted Control Sphere in IntelliJ IDEA - CVE-2026-86504

 

Inclusion of Functionality from Untrusted Control Sphere in IntelliJ IDEA - CVE-2026-86504

Published: September 7, 2026


Vulnerability identifier: #VU147333
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-86504
CWE-ID: CWE-829
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute code on the host system.

The vulnerability exists due to improper control of functionality from an untrusted control sphere in the Dev Container build process when building a Dev Container from an untrusted project. A remote attacker can build a Dev Container from an untrusted project to execute code on the host system.


Affected software

IntelliJ IDEA

How to mitigate CVE-2026-86504

Install security update from vendor's website.

IntelliJ IDEA - update to 2026.2.2

External References

Related Security Bulletins