VulnSea

jetbrains has 49 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 46 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 29. The median CVSS is 6.5 (medium), with 4 rated critical. 2% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-862 (10) and CWE-306 (5). Most affected products: YouTrack (30), intellij_idea (6), IntelliJ IDEA (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
2% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—(1)
Last 90 days
46 prev 0

Products

  • YouTrack 30
  • intellij_idea 6
  • IntelliJ IDEA 5
  • pycharm 2
  • GoLand 1
  • Hub 1
49
Total CVEs
4
Critical
1
CISA KEV
1
Exploited

jetbrains vulnerabilities

CVEs affecting jetbrains, newest first. Open any entry for full detail, references, and exploit status.

49 CVEsRSS

CVE-2026-75049Medium· 6.5
1mo ago

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint

▾ Sunlitjetbrains · youtrackEPSS 0.34%via NVD
CVE-2026-75048High· 8.2
1mo ago

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

▾ Twilightjetbrains · youtrackEPSS 0.32%via NVD
CVE-2026-75047Medium· 6.5
1mo ago

In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint

In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint

▾ Sunlitjetbrains · youtrackEPSS 1.2%via NVD
CVE-2026-75046Medium· 4.3
1mo ago

In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint

In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint

▾ Sunlitjetbrains · youtrackEPSS 0.27%via NVD
CVE-2026-75045Critical· 9.1
1mo ago

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

▾ Midnightjetbrains · youtrackEPSS 0.42%via NVD
CVE-2026-75044High· 8.1
1mo ago

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint

▾ Twilightjetbrains · youtrackEPSS 0.38%via NVD
CVE-2026-75051High· 8.1
1mo ago

In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible

In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible

▾ Twilightjetbrains · youtrackEPSS 0.35%via NVD
CVE-2026-75055Medium· 5.5
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

▾ Sunlitjetbrains · intellij_ideaEPSS 0.15%via NVD
CVE-2026-75059Medium· 4.4
1mo ago

In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible

In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible

▾ Sunlitjetbrains · pycharmEPSS 0.18%via NVD
CVE-2026-75057Medium· 6.2
1mo ago

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

▾ Sunlitjetbrains · intellij_ideaEPSS 0.17%via NVD
CVE-2026-75058Medium· 5.5
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers

In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers

▾ Sunlitjetbrains · intellij_ideaEPSS 0.15%via NVD
CVE-2026-75054Medium· 6.3
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

▾ Sunlitjetbrains · intellij_ideaEPSS 0.15%via NVD
CVE-2026-75060High· 8.4
1mo ago

In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools

In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools

▾ Twilightjetbrains · pycharmEPSS 0.18%via NVD
CVE-2026-75056High· 7.8
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

▾ Twilightjetbrains · intellij_ideaEPSS 0.19%via NVD
CVE-2026-75053Medium· 5.4
1mo ago

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

▾ Sunlitjetbrains · intellij_ideaEPSS 0.24%via NVD
CVE-2026-63077Critical· 9.8CISA KEVPoC
2mo ago

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

▾ HadalJetBrains · TeamCityEPSS 9.8%via CVEORG
CVE-2025-64457Medium· 4.2
10mo ago

In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition

In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition

▾ Sunlitjetbrains · dottraceEPSS 0.09%via NVD
CVE-2025-58335Medium· 5.5
1y ago

In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function

In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function

▾ Sunlitjetbrains · junieEPSS 0.22%via NVD
CVE-2025-58334High· 8.1
1y ago

In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves

In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves

▾ Twilightjetbrains · ide_servicesEPSS 0.29%via NVD
jetbrains vulnerabilities (CVEs) — page 2 · VulnSea