
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-64808 is an arbitrary code execution vulnerability in JetBrains PhpStorm affecting all versions before 2026.2. The flaw allows code execution to occur before a user grants project trust via project tooling, bypassing a key security boundary in the IDE. It was published on July 23, 2026, with JetBrains as the assigning CNA. The vulnerability carries a CVSS v3.1 base score of 8.4 (High), assigned by JetBrains (GitHub Advisory, JetBrains).
The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), meaning PhpStorm imports or executes functionality from an untrusted source — specifically via project tooling — before the user has explicitly granted trust to the project. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), with low attack complexity (AC:L). In practice, an attacker could craft a malicious project with specially configured tooling that triggers code execution as soon as the project is opened in PhpStorm, before the IDE's trust prompt is presented or acted upon. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, JetBrains).
Successful exploitation grants an unauthenticated local attacker arbitrary code execution with the full privileges of the PhpStorm application process, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive files accessible to the IDE process, modify project files or system resources, and potentially disrupt the development environment. The scope is limited to the local system running the vulnerable PhpStorm instance, but the compromise of a developer workstation could facilitate further lateral movement into source code repositories, CI/CD pipelines, or connected infrastructure (GitHub Advisory).
JetBrains has released a fix in PhpStorm version 2026.2; upgrading to this version or later is the recommended remediation. Until an upgrade is possible, users should restrict local access to systems running vulnerable PhpStorm versions and exercise caution when opening projects from untrusted or unknown sources. Avoid opening projects received via email, messaging platforms, or unfamiliar repositories on unpatched installations (JetBrains, GitHub Advisory).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"