CVE-2026-59792Patch(jetbrains / intellij_idea)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jetbrains intellij_idea systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • intellij_idea

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-07-10); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
intellij_idea

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-07-10: 1Mentions · 2026-07-13: 1Mentions · 2026-07-15: 1Mentions · 2026-07-16: 1Mentions · 2026-07-24: 1Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-24: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-13: 1Technical Details · 2026-07-15: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-24: 107-1007-1307-1507-1607-24
Signal classification2 categories
Patch
480.0%
Disclosure
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-101
Patch1
2026-07-131
Disclosure1
2026-07-151
Patch1
2026-07-161
Patch1
2026-07-241
Patch1
Full discourse5 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    JetBrains vulnerabilities patched: CVE-2026-62422 (CVSS 10) YouTrack authentication bypass, IntelliJ IDEA RCE CVE-2026-59792, and four TeamCity flaws. #JetBrains #YouTrack #IntelliJIDEA #TeamCity #CVE http://securityonline.info/jetbrains-vulnerabilities/

    Post summary

    JetBrains has released patches for several high‑severity CVEs, including a CVSS 10 authentication bypass in YouTrack and an RCE in IntelliJ IDEA, along with four additional TeamCity flaws.

    01010360
    12.5K followersView on X
  • TECHEPAGES@techepages
    Patch

    JetBrains has released security updates addressing a critical code execution vulnerability in IntelliJ IDEA (CVE-2026-59792, path traversal in workspace ID handling) and four high-severity vulnerabilities in TeamCity, including a critical RCE flaw in Git VCS roots (CVE-2026-65907). Development teams and CI administrators are urged to upgrade immediately to IntelliJ IDEA 2026.1.4/2026.2 and TeamCity 2026.1.2/2025.11.6.

    Post summary

    JetBrains released patch updates for critical vulnerabilities in IntelliJ IDEA and TeamCity, urging immediate upgrades to specified versions.

    0000082
    32 followersView on X
  • TECHEPAGES@techepages
    Patch

    🛠️ JetBrains just patched six vulnerabilities across IntelliJ IDEA, TeamCity, and YouTrack — the worst (CVE-2026-59792, Critical) is a path traversal flaw in IntelliJ that could enable remote code execution. Developers should update now. Key fixes: 🔹 IntelliJ IDEA → 2026.1.4 or 2026.2 🔹 TeamCity → 2026.1.2 (fixes arbitrary file access + 2 stored XSS bugs) 🔹 CI/CD pipeline permission flaw could let unauthorized users tamper with builds 🔹 YouTrack → 2026.2.17012 (low-severity CSS injection)

    Post summary

    JetBrains released patches for six vulnerabilities, including a critical path traversal flaw in IntelliJ IDEA, urging developers to update immediately.

    0000046
    23 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 CRITICAL: JetBrains IntelliJ IDEA + TeamCity — CVSS 9.6 + 7.3 CVE-2026-59792: Path traversal in workspace ID handling → RCE on developer machine CVE-2026-59794: Stored XSS via agent-reported data in TeamCity → http://threataft.com/articles/jetbrains-intellij-teamcity-cve-2026-59792-59794 #cybersecurity #infosec #JetBrains

    Post summary

    JetBrains IntelliJ IDEA and TeamCity vulnerabilities CVE-2026-59792 (path traversal leading to RCE) and CVE-2026-59794 (stored XSS) are announced with high CVSS scores.

    0000061
    34 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - JetBrains IntelliJ IDEA Code Execution via Workspace-ID Path Traversal (CVE-2026-59792) IntelliJ IDEA improperly handles the project workspace ID, allowing a relative path traversal that can be leveraged to execute code. It fits the classic malicious-project threat model: a developer opening or working with an attacker-influenced project can trigger code execution on their machine. Per JetBrains' scoring it's network, low complexity, no privileges, requires user interaction, with a scope change and high confidentiality/integrity impact (CVSS 9.6). JetBrains limits public technical detail by policy. 👉Update IntelliJ IDEA to 2026.1.4 or 2026.2.

    Post summary

    The tweet announces a critical code‑execution vulnerability (CVE‑2026‑59792) in IntelliJ IDEA, outlines its technical details, and urges users to update to the latest patch versions 2026.1.4 or 2026.2 to mitigate the risk.

    0000080
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjetbrainsintellij_idea---

Explore more