PatchSiren cyber security CVE debrief
CVE-2026-86502 JetBrains CVE debrief
CVE-2026-86502 debrief based on the supplied source corpus. The IJent gRPC server in JetBrains IntelliJ IDEA before 2026.2.2 lacks TLS and authentication, allowing local code execution on Remote Development hosts. This vulnerability affects Remote Development hosts and JetBrains IntelliJ IDEA installations, with potential for unauthorized access to sensitive data. Defenders should assess exposure and prioritize updates to JetBrains IntelliJ IDEA 2026.2.2 or later. The CVE record and NVD entry indicate that JetBrains IntelliJ IDEA before 2026.2.2 has a missing TLS and authentication on the IJent gRPC server.
- Vendor
- JetBrains
- Product
- IntelliJ IDEA
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for Remote Development hosts and JetBrains IntelliJ IDEA installations should assess exposure and prioritize updates. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify the configuration of IJent gRPC servers and ensure the security of Remote Development hosts. They should also review compensating controls for exposed systems,
Why it matters
CVE-2026-86502 allows local code execution on Remote Development hosts due to missing TLS and authentication on the IJent gRPC server in JetBrains IntelliJ IDEA before 2026.2.2.
- Local code execution on Remote Development hosts
- Potential for unauthorized access to sensitive data
- Need for verification of IJent gRPC server configuration
- Priority for updating to JetBrains IntelliJ IDEA 2026.2.2 or later
Technical summary
The IJent gRPC server in JetBrains IntelliJ IDEA before 2026.2.2 lacks TLS and authentication, allowing local code execution on Remote Development hosts. This vulnerability is due to missing security measures in the IJent gRPC server, which could lead to unauthorized access and data breaches. Defenders should verify Remote Development hosts and update to JetBrains IntelliJ IDEA 2026.2.2 or later.
Defensive priority
Defenders should prioritize verification of Remote Development hosts and update to JetBrains IntelliJ IDEA 2026.2.2 or later.
Recommended defensive actions
- Verify Remote Development hosts for exposure to the IJent gRPC server
- Update to JetBrains IntelliJ IDEA 2026.2.2 or later
- Monitor for local code execution attempts on Remote Development hosts
Evidence notes
The CVE record and NVD entry indicate that JetBrains IntelliJ IDEA before 2026.2.2 has a missing TLS and authentication on the IJent gRPC server, allowing local code execution on Remote Development hosts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86502 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86502
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86502 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86502
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jetbrains.com/privacy-security/issues-fixed/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.