JetBrains Creators of IntelliJ IDEA, ReSharper, PyCharm, TeamCity, Kotlin
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any JetBrains product.
RSS Feeds for JetBrains security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in JetBrains products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by JetBrains Sorted by Most Security Vulnerabilities since 2018
Known Exploited JetBrains Vulnerabilities
The following JetBrains vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| JetBrains TeamCity Deserialization of Untrusted Data Vulnerability |
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. CVE-2026-63077 |
August 5, 2026 |
| JetBrains TeamCity Relative Path Traversal Vulnerability |
JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed. CVE-2024-27199 Exploit Probability: 100.0% |
April 20, 2026 |
| JetBrains TeamCity Authentication Bypass Vulnerability |
JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions. CVE-2024-27198 Exploit Probability: 99.9% |
March 7, 2024 |
| JetBrains TeamCity Authentication Bypass Vulnerability |
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server. CVE-2023-42793 Exploit Probability: 100.0% |
October 4, 2023 |
Of the known exploited vulnerabilities above, 3 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 116 vulnerabilities in JetBrains with an average score of 6.6 out of ten. Last year, in 2025 JetBrains had 84 security vulnerabilities published. That is, 32 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.54.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 116 | 6.61 |
| 2025 | 84 | 6.07 |
| 2024 | 103 | 6.20 |
| 2023 | 54 | 6.54 |
| 2022 | 75 | 6.48 |
| 2021 | 88 | 6.66 |
| 2020 | 57 | 6.38 |
| 2019 | 57 | 8.28 |
| 2018 | 2 | 0.00 |
It may take a day or so for new JetBrains vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent JetBrains Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-86506 | Sep 07, 2026 |
GoLand Pprof Profiler Auth Bypass before 2026.2.2.1In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data |
|
| CVE-2026-86505 | Sep 07, 2026 |
IntelliJ IDEA <2026.2.2: project metadata leak due to missing trust checkIn JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace |
|
| CVE-2026-86504 | Sep 07, 2026 |
IntelliJ IDEA <2026.2.2 Dev Container RCE missing project-trust confirmationIn JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution |
|
| CVE-2026-86503 | Sep 07, 2026 |
IntelliJ IDEA <2026.2.2 SSRF via Kubernetes spec-source URL fetchingIn JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching |
|
| CVE-2026-86502 | Sep 07, 2026 |
IntelliJ IDEA <2026.2.2 gRPC TLS/Auth Bypass LCEIn JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts |
|
| CVE-2026-86501 | Sep 07, 2026 |
IntelliJ IDEA <2026.2.2 Terminal Cmd Log InjectionIn JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log |
|
| CVE-2026-86500 | Sep 07, 2026 |
JetBrains YouTrack <2026.1.14047: Escalation Check Bypass Grants AdminIn JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin |
|
| CVE-2026-86499 | Sep 07, 2026 |
YouTrack pre-2026.1.14047: Predefined search fields leak group namesIn JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission |
|
| CVE-2026-86498 | Sep 07, 2026 |
YouTrack <2025.3.160480: Unauthorized PUT on Link Sub-ResourcesIn JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission |
|
| CVE-2026-86497 | Sep 07, 2026 |
YouTrack <=2026.2.18769 Credential Exfiltration via Mailbox Host ChangeIn JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials |
|
| CVE-2026-86496 | Sep 07, 2026 |
JetBrains YouTrack <2026.2.18769: Helpdesk Reporter Email ExposureIn JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses |
|
| CVE-2026-86495 | Sep 07, 2026 |
JetBrains YouTrack < 2026.2.18687 Missing Permission Checks for KB ArticlesIn JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects |
|
| CVE-2026-86494 | Sep 07, 2026 |
YouTrack <2026.2.18634: Whiteboard clone allows unauthorized link changesIn JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues |
|
| CVE-2026-86493 | Sep 07, 2026 |
YouTrack < 2026.2.18634 Checks Let Read-Only Users Modify Whiteboard CardsIn JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards |
|
| CVE-2026-86492 | Sep 07, 2026 |
YouTrack < 2026.2.18634 Cross-Tenant GitHub App Token Theft via Shared CacheIn JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens |
|
| CVE-2026-86491 | Sep 07, 2026 |
YouTrack XSS via Project/Org Icon Uploads (pre2026.2.18634)In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads |
|
| CVE-2026-86490 | Sep 07, 2026 |
YouTrack <2026.2.18634 Improper Permission Checks Overwrite Bundled AppsIn JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint |
|
| CVE-2026-86489 | Sep 07, 2026 |
JetBrains YouTrack IDOR in User Profile API before 2026.2.18634In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations |
|
| CVE-2026-86488 | Sep 07, 2026 |
JetBrains YouTrack <2026.2.18634 iDOR via watchRules & issueListConfigIn JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches |
|
| CVE-2026-86487 | Sep 07, 2026 |
YouTrack WebSocket Canvas Injection before 2026.2.18634In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content |
|
| CVE-2026-86486 | Sep 07, 2026 |
YouTrack VCS Webhook Handler Allows Open Access with Blank Secret <2026.2.18634In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank |
|
| CVE-2026-86485 | Sep 07, 2026 |
JetBrains YouTrack <2026.2.18634: IP Spoofing via Headers Bitbucket WebhooksIn JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks |
|
| CVE-2026-86484 | Sep 07, 2026 |
YouTrack <2026.2.18634 AngularJS Template Injection XSSIn JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS |
|
| CVE-2026-86483 | Sep 07, 2026 |
JetBrains YouTrack XSS via Agile Board Custom Field (< 2026.2.18634)In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible |
|
| CVE-2026-86482 | Sep 07, 2026 |
JetBrains YouTrack < 2026.2.18634 PrivEsc via Unchecked Group MembershipIn JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation |
|
| CVE-2026-86481 | Sep 07, 2026 |
JetBrains YouTrack 2026.2.18634 Signed URL Reuse DisclosureIn JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons |
|
| CVE-2026-86480 | Sep 07, 2026 |
JetBrains Hub: Unauth Trusted Service Grants Superuser (pre-2026.2.52442)In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges |
|
| CVE-2026-86479 | Sep 07, 2026 |
JetBrains YouTrack 2026.2.18788 IDOR: Unauthorized REST API AccessIn JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR |
|
| CVE-2026-86478 | Sep 07, 2026 |
YouTrack <2025.3.161254 & 2026.1.14042 Unauth TakeoverIn JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address |
|
| CVE-2026-75060 | Aug 17, 2026 |
Unauthenticated code exec in JetBrains PyCharm <2026.2.1 via Jupyter MCPIn JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools |
|
| CVE-2026-75059 | Aug 17, 2026 |
JetBrains PyCharm Code Execution via Quick Documentation (Before 2026.2.1)In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible |
|
| CVE-2026-75058 | Aug 17, 2026 |
IntelliJ IDEA Pre2026.2.1 xXE via Eclipse Settings ImporterIn JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers |
|
| CVE-2026-75057 | Aug 17, 2026 |
IntelliJ IDEA <2026.1.5 - Git Credentials Logged in PlaintextIn JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log |
|
| CVE-2026-75056 | Aug 17, 2026 |
Remote Code Exec in IntelliJ IDEA <2026.2.1 via Markdown ExportIn JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible |
|
| CVE-2026-75055 | Aug 17, 2026 |
IntelliJ IDEA <2026.2.1, Hadoop ResourceManager XXE Local File ReadIn JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE |
|
| CVE-2026-75054 | Aug 17, 2026 |
IntelliJ IDEA <2026.2.1 sSRF via OpenAPI preview proxyIn JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects |
|
| CVE-2026-75053 | Aug 17, 2026 |
SRF in JetBrains IntelliJ IDEA < 2026.2.1 via DevKit Debug ListenerIn JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint |
|
| CVE-2026-75052 | Aug 17, 2026 |
CVE-2026-75052: CMD exec via Markdown preview in IntelliJ IDEA < 2026.2.1In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projects |
|
| CVE-2026-75050 | Aug 17, 2026 |
YouTrack DoS via crafted type params in <2026.1.13901 & 2026.2.17950In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters |
|
| CVE-2026-75051 | Aug 17, 2026 |
YouTrack 2026.2.17917: Unauthorized Project Transfer Between OrgsIn JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible |
|
| CVE-2026-75049 | Aug 17, 2026 |
YouTrack Auth Read Rstrctd Articles via Draft-Create EP (v1.13903/v2.17950)In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint |
|
| CVE-2026-75048 | Aug 17, 2026 |
JetBrains YouTrack <2026.2.18068 XSS via Code LabelIn JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible |
|
| CVE-2026-75047 | Aug 17, 2026 |
JetBrains YouTrack DoS via decompression bomb (pre-2026.2.18177)In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint |
|
| CVE-2026-75046 | Aug 17, 2026 |
YouTrack <=2026.2.18112: Auth User Enum via Search (CVE-2026-75046)In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint |
|
| CVE-2026-75045 | Aug 17, 2026 |
JetBrains YouTrack < 2025.3.156085, 2026.x: Unauth DB backup via draft sigIn JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature |
|
| CVE-2026-68762 | Aug 17, 2026 |
Ktor WebSocket Decompression DoS before 3.4.1In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible |
|
| CVE-2026-75044 | Aug 17, 2026 |
JetBrains YouTrack 2026.2.18095: Auth Deletion via Mailbox EndptIn JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint |
|
| CVE-2026-63077 | Jul 27, 2026 |
JetBrains TeamCity <2026.1.3 Remote Code Execution via Agent PollingIn JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol |
|
| CVE-2026-65907 | Jul 23, 2026 |
TeamCity <2026.1.2 Git VCS CodeExec VulnerabilityIn JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible |
|
| CVE-2026-65908 | Jul 23, 2026 |
JetBrains PyCharm <2026.1.4, 2026.2 Arbitrary Exec via Malicious PythonIn JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open |
|