← Vulnerability feed

Vulnerability record · CVE-2026-75060 · published 17 August 2026

CVE-2026-75060: Jetbrains pycharm missing authentication for critical function vulnerability

Jetbrains · Pycharm

In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools

8.4 CVSS 3.1 High EPSS 0.18% · top 93.0% CWE-306 · Missing authentication for critical function
8.4CVSS 3.1 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
10 Sep 2026Last modified by NVD

Description

In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-75060 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-45977Jetbrains clion vulnerabilityJetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, Ph…EPSS 1.1%8.6CVE-2026-65908Jetbrains pycharm inclusion from untrusted sphere vulnerabilityIn JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project openEPSS 0.19%7.8CVE-2021-30005Jetbrains pycharm insufficient verification of data authenticity vulnerabilityIn JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.EPSS 0.88%7.7CVE-2022-29821Jetbrains pycharm code injection vulnerabilityIn JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possibleEPSS 0.23%7.5CVE-2024-37051Jetbrains aqua insufficiently protected credentials vulnerabilityGitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 202…EPSS 3.8%7.5CVE-2020-11694Jetbrains pycharm cleartext storage of sensitive data vulnerabilityIn JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.EPSS 1.9%7.5CVE-2019-14958Jetbrains pycharm allocation without limits vulnerabilityJetBrains PyCharm before 2019.2 was allocating a buffer of unknown size for one of the connection processes. In a very specific situation, it could l…EPSS 1.9%6.1CVE-2026-49384Jetbrains pycharm cross-site scripting vulnerabilityIn JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possibleEPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2026-75060), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.