PatchSiren cyber security CVE debrief
CVE-2026-86506 JetBrains CVE debrief
CVE-2026-86506 debrief based on CVE Program and NVD records. The vulnerability affects JetBrains GoLand before version 2026.2.2.1, exposing profiling data due to missing authentication on the profiler's injected pprof server. This MEDIUM-severity issue, with a CVSS score of 5.9, requires users and administrators to assess exposure and verify patching to prevent potential data exposure. The CVE record and NVD entry provide limited information, emphasizing the need for users to review and update their deployments.
- Vendor
- JetBrains
- Product
- GoLand
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
JetBrains GoLand users and administrators should assess exposure and verify patching to prevent potential data exposure. This involves reviewing the current version of GoLand in use, updating to version 2026.2.2.1 or later if necessary, and ensuring that access to the profiler's pprof server is properly restricted. Additionally, users should monitor for potential unauthorized access or data exposure and review their
Why it matters
CVE-2026-86506 is a MEDIUM-severity vulnerability in JetBrains GoLand that exposes profiling data due to missing authentication on the profiler's pprof server. JetBrains GoLand users and administrators should assess exposure, verify patching, and limit access to prevent potential data exposure.
- Verify patching to prevent potential profiling data exposure.
- Assess and limit access to the GoLand profiler's pprof server.
- Monitor for potential unauthorized access or data exposure.
- Review and update inventory of GoLand deployments.
Technical summary
The CVE-2026-86506 vulnerability in JetBrains GoLand before version 2026.2.2.1 involves missing authentication on the profiler's injected pprof server, potentially exposing profiling data. The CVSS score is 5.9 (MEDIUM severity). This issue arises from the lack of authentication mechanisms on the pprof server, which could allow unauthorized access to profiling data. Users should assess their exposure, verify patching to version 2026.2.2.1 or later, and restrict access to the pprof server to mitigate potential risks.
Defensive priority
Assess exposure and verify patching for JetBrains GoLand users
Recommended defensive actions
- Assess exposure: Review JetBrains GoLand usage and versions in your environment.
- Verify patching: Check if the patched version 2026.2.2.1 or later is deployed.
- Restrict access: Limit access to the GoLand profiler's pprof server.
- Monitor for issues: Watch for potential data exposure or unauthorized access.
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, which is described as missing authentication on the GoLand profiler's injected pprof server, potentially exposing profiling data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-86506 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-86506
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-86506 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86506
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jetbrains.com/privacy-security/issues-fixed/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.