Threat Advisory

IntelliJ IDEA and TeamCity Flaws Enable Arbitrary Code Execution

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting JetBrains versions JetBrains lists fix versions rather than affected ranges have been identified in JetBrains products, including GoLand, IntelliJ IDEA, PhpStorm, PyCharm, TeamCity, and WebStorm. These vulnerabilities pose a significant risk to users, particularly those who rely on these tools for development workstations that hold source code, cloud tokens, and signing keys. Affected version ranges include versions older than the fix in 2026.2 for GoLand, IntelliJ IDEA, PhpStorm, and WebStorm, 2026.1.4 and 2026.2 for PyCharm, and 2026.1.2 and 2025.11.6 for TeamCity.

CVE-2026-64812 (CVSS 10.0 — Critical): This vulnerability allows remote development flaws enabling arbitrary code execution in IntelliJ IDEA.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting JetBrains versions JetBrains lists fix versions rather than affected ranges have been identified in JetBrains products, including GoLand, IntelliJ IDEA, PhpStorm, PyCharm, TeamCity, and WebStorm. These vulnerabilities pose a significant risk to users, particularly those who rely on these tools for development workstations that hold source code, cloud tokens, and signing keys. Affected version ranges include versions older than the fix in 2026.2 for GoLand, IntelliJ IDEA, PhpStorm, and WebStorm, 2026.1.4 and 2026.2 for PyCharm, and 2026.1.2 and 2025.11.6 for TeamCity.

CVE-2026-64812 (CVSS 10.0 — Critical): This vulnerability allows remote development flaws enabling arbitrary code execution in IntelliJ IDEA.[emaillocker id="1283"]

CVE-2026-64813 (CVSS 10.0 — Critical): This vulnerability allows unauthorized settings changes in a Remote Development session in IntelliJ IDEA.

CVE-2026-65907 (CVSS 9.1 — Critical): This vulnerability permits code execution through Git VCS roots in TeamCity.

CVE-2026-65906 (CVSS 8.8 — High): This vulnerability allows a Kotlin DSL sandbox escape in TeamCity.

CVE-2026-64814 (CVSS 8.6 — High): This vulnerability allows unauthorized file access in IntelliJ IDEA.

CVE-2026-65908 (CVSS 8.6 — High): This vulnerability allows CWE-829 in PyCharm.

CVE-2026-64804 (CVSS 8.4 — High): This vulnerability allows CWE-829 in GoLand, IntelliJ IDEA, PhpStorm, and WebStorm.

CVE-2026-64805 (CVSS 8.4 High ): This vulnerability allows CWE-829 in GoLand, IntelliJ IDEA, PhpStorm, and WebStorm. These vulnerabilities collectively present a risk to development workstations that hold source code, cloud tokens, and signing keys. Administrators should update through the Toolbox App or their IDE’s built-in updater as soon as possible. These vulnerabilities collectively present a risk to development workstations that hold source code, cloud tokens, and signing keys.

These vulnerabilities collectively present a risk to development workstations that hold source code, cloud tokens, and signing keys.

RECOMMENDATION:

We recommend you to update JetBrains products to given version link: https://www.jetbrains.com/privacy-security/issues-fixed/

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu