CVE-2026-41882

EUVD-2026-26368
In JetBrains IntelliJ IDEA before 2024.3.7.1, 
2025.1.7.1,
2025.2.6.2,  
2025.3.4.1, 
2026.1.1 reading arbitrary local files was possible via built-in web server
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
jetbrainsintellij_idea
2024.3.7.1
jetbrainsintellij_idea
2025.1.7.1
jetbrainsintellij_idea
2025.2.6.2
jetbrainsintellij_idea
2025.3.4.1
jetbrainsintellij_idea
2026.1.1
𝑥
= Vulnerable software versions