Review reviewHigh
CVE-2026-49366
JetBrains IntelliJ IDEA, intellij idea
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
- CVSS
- 7.8
- EPSS
- 0.46% 37.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.30
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
The CVSS severity warrants an early asset and exposure review.
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
Confirm exposure before applying a vendor-supported change.
Confirm that JetBrains IntelliJ IDEA, intellij idea and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.