PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86502 JetBrains CVE debrief

CVE-2026-86502 debrief based on the supplied source corpus. The IJent gRPC server in JetBrains IntelliJ IDEA before 2026.2.2 lacks TLS and authentication, allowing local code execution on Remote Development hosts. This vulnerability affects Remote Development hosts and JetBrains IntelliJ IDEA installations, with potential for unauthorized access to sensitive data. Defenders should assess exposure and prioritize updates to JetBrains IntelliJ IDEA 2026.2.2 or later. The CVE record and NVD entry indicate that JetBrains IntelliJ IDEA before 2026.2.2 has a missing TLS and authentication on the IJent gRPC server.

Vendor
JetBrains
Product
IntelliJ IDEA
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

Defenders responsible for Remote Development hosts and JetBrains IntelliJ IDEA installations should assess exposure and prioritize updates. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify the configuration of IJent gRPC servers and ensure the security of Remote Development hosts. They should also review compensating controls for exposed systems,

Why it matters

CVE-2026-86502 allows local code execution on Remote Development hosts due to missing TLS and authentication on the IJent gRPC server in JetBrains IntelliJ IDEA before 2026.2.2.

  • Local code execution on Remote Development hosts
  • Potential for unauthorized access to sensitive data
  • Need for verification of IJent gRPC server configuration
  • Priority for updating to JetBrains IntelliJ IDEA 2026.2.2 or later

Technical summary

The IJent gRPC server in JetBrains IntelliJ IDEA before 2026.2.2 lacks TLS and authentication, allowing local code execution on Remote Development hosts. This vulnerability is due to missing security measures in the IJent gRPC server, which could lead to unauthorized access and data breaches. Defenders should verify Remote Development hosts and update to JetBrains IntelliJ IDEA 2026.2.2 or later.

Defensive priority

Defenders should prioritize verification of Remote Development hosts and update to JetBrains IntelliJ IDEA 2026.2.2 or later.

Recommended defensive actions

  • Verify Remote Development hosts for exposure to the IJent gRPC server
  • Update to JetBrains IntelliJ IDEA 2026.2.2 or later
  • Monitor for local code execution attempts on Remote Development hosts

Evidence notes

The CVE record and NVD entry indicate that JetBrains IntelliJ IDEA before 2026.2.2 has a missing TLS and authentication on the IJent gRPC server, allowing local code execution on Remote Development hosts.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86502 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86502

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86502 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86502

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.