← Vulnerability feed

Vulnerability record · CVE-2026-49366 · published 29 May 2026

CVE-2026-49366: Jetbrains intellij idea os command injection vulnerability

Jetbrains · Intellij Idea

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

7.8 CVSS 3.1 High EPSS 0.68% · top 49.7% CWE-78 · OS command injection
7.8CVSS 3.1 base score
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
22 Jul 2026Last modified by NVD

Description

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-49366 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-64812Jetbrains intellij idea missing authentication for critical function vulnerabilityIn JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development sessionEPSS 0.48%10.0CVE-2026-64813Jetbrains intellij idea vulnerabilityIn JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development sessionEPSS 0.52%9.8CVE-2026-64815Jetbrains intellij idea code injection vulnerabilityIn JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form filesEPSS 0.48%9.8CVE-2026-59792Jetbrains intellij idea relative path traversal vulnerabilityIn JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possibleEPSS 0.61%9.8CVE-2023-51655Jetbrains intellij idea insufficient verification of data authenticity vulnerabilityIn JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the p…EPSS 0.33%9.8CVE-2021-45977Jetbrains clion vulnerabilityJetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, Ph…EPSS 1.1%9.8CVE-2020-11690Jetbrains intellij idea vulnerabilityIn JetBrains IntelliJ IDEA before 2020.1, the license server could be resolved to an untrusted host in some cases.EPSS 2.3%9.8CVE-2019-9186Jetbrains intellij idea exposure of resource to wrong sphere vulnerabilityIn several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default setting allowed remote attackers to execute code when t…EPSS 4.5%

Source: NIST National Vulnerability Database (record CVE-2026-49366), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.