High severity7.4NVD Advisory· Published Apr 30, 2026· Updated May 5, 2026
CVE-2026-41882
CVE-2026-41882
Description
In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server
Affected products
5cpe:2.3:a:jetbrains:intellij_idea:2024.3.7.1:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:jetbrains:intellij_idea:2024.3.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:jetbrains:intellij_idea:2025.1.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:jetbrains:intellij_idea:2025.2.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:jetbrains:intellij_idea:2025.3.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:jetbrains:intellij_idea:2026.1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.jetbrains.com/privacy-security/issues-fixed/nvdVendor Advisory
News mentions
0No linked articles in our index yet.