
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86502 is a missing TLS and authentication vulnerability in JetBrains IntelliJ IDEA's IJent gRPC server that allows local code execution on Remote Development hosts. It affects all versions of IntelliJ IDEA before 2026.2.2 and was published on September 7, 2026. The vulnerability carries a CVSS v3.1 base score of 8.4 (High), classified under CWE-306 (Missing Authentication for Critical Function) (GitHub Advisory, JetBrains).
The root cause is the absence of TLS encryption and authentication controls on the IJent gRPC server component used in IntelliJ IDEA's Remote Development feature (CWE-306). Because the gRPC server neither enforces transport-layer security nor requires caller authentication, any local user on the Remote Development host can connect to the service and issue arbitrary commands. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), making exploitation straightforward for any user with local access to the affected host (GitHub Advisory, JetBrains).
Successful exploitation allows any local user on a Remote Development host to execute arbitrary code with the privileges of the IJent gRPC server process, resulting in high confidentiality, integrity, and availability impact. An attacker could gain full control of the remote host environment, access sensitive source code and credentials stored in the IDE, and potentially pivot to other systems accessible from the compromised host (GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation is currently "none" and the attack is not automatable. The EPSS score is approximately 0.144% (4th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
ss -tlnp or netstat -tlnp on Linux).grpcurl or a custom gRPC client) to connect directly to the IJent gRPC server endpoint without providing any credentials or TLS certificates, since neither is enforced.The primary remediation is to upgrade JetBrains IntelliJ IDEA to version 2026.2.2 or later, which adds TLS and authentication to the IJent gRPC server (JetBrains, GitHub Advisory). As a temporary workaround, administrators should restrict local access to Remote Development hosts to trusted users only, and use host-based firewall rules or network segmentation to limit which processes and users can connect to the IJent gRPC service port. Isolating Remote Development hosts in environments with strict multi-user access controls reduces the attack surface until patching is possible.
The vulnerability received routine coverage from vulnerability tracking services including CVEFeed, VulDB, and Vulners shortly after disclosure on September 7, 2026. Social media mentions appeared on Mastodon and Bluesky via automated CVE tracking accounts. No notable independent researcher commentary or significant media coverage beyond standard vulnerability aggregation has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."