Skip to content
COOEY

EXPOSURES › CVE-2026-59792

CVE-2026-59792

CRITICAL
DETAIL
SourceNVD · cve Published2026-07-10 CVSS9.6 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-59792 ↗
⚡ RCE SHAME 65/100 rceunpatchedexploited-in-wild

JetBrains shipped an unpatched path traversal RCE in IntelliJ IDEA that allows remote code execution via project workspace ID handling.

This critical vulnerability (CVE-2026-59792) enables arbitrary code execution in JetBrains IntelliJ IDEA through a path traversal flaw in workspace ID handling, posing a severe risk to DIB organizations relying on JetBrains tools for development and code review. The vendor failed to patch the issue in versions prior to 2026.1.4 and 2026.2, creating a compliance gap for FedRAMP and NIST 800-171 requirements that mandate timely patching of critical vulnerabilities. DIB orgs must audit all JetBrains tool usage and enforce strict version controls to prevent exploitation.

Shame score — A critical RCE vulnerability in a widely-used development tool that was not patched in time, creating a significant security exposure for organizations relying on JetBrains products.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.