jetbrains has 49 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 46 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 29. The median CVSS is 6.5 (medium), with 4 rated critical. 2% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-862 (10) and CWE-306 (5). Most affected products: YouTrack (30), intellij_idea (6), IntelliJ IDEA (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 2% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —(1)
- Last 90 days
- 46 prev 0
Weakness classes
Products
- YouTrack 30
- intellij_idea 6
- IntelliJ IDEA 5
- pycharm 2
- GoLand 1
- Hub 1
Worst active — by depth score
CVE-2026-63077Critical· 9.8In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol86CVE-2026-86480Critical· 9.8In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges54CVE-2026-86478Critical· 9.8In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address54CVE-2026-75045Critical· 9.1In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature50CVE-2026-86482High· 8.8In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation48
jetbrains vulnerabilities
CVEs affecting jetbrains, newest first. Open any entry for full detail, references, and exploit status.
49 CVEsRSS
CVE-2026-75049Medium· 6.5In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
CVE-2026-75048High· 8.2In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
CVE-2026-75047Medium· 6.5In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint
CVE-2026-75046Medium· 4.3In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
CVE-2026-75045Critical· 9.1In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
CVE-2026-75044High· 8.1In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
CVE-2026-75051High· 8.1In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible
CVE-2026-75055Medium· 5.5In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
CVE-2026-75059Medium· 4.4In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible
CVE-2026-75057Medium· 6.2In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
CVE-2026-75058Medium· 5.5In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
CVE-2026-75054Medium· 6.3In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
CVE-2026-75060High· 8.4In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools
CVE-2026-75056High· 7.8In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
CVE-2026-75053Medium· 5.4In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint
CVE-2026-63077Critical· 9.8CISA KEVPoCIn JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
CVE-2025-64457Medium· 4.2In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
CVE-2025-58335Medium· 5.5In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function
CVE-2025-58334High· 8.1In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves
In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves