Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ |
|
Tue, 04 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Code Injection through UI Designer Form Files in IntelliJ IDEA 2026.1 and Earlier |
Sun, 02 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Code Injection through UI Designer Form Files in IntelliJ IDEA 2026.1 and Earlier |
Thu, 30 Jul 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Code Injection via UI Designer Form Files in IntelliJ IDEA |
Mon, 27 Jul 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Code Injection via UI Designer Form Files in IntelliJ IDEA |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jetbrains
Jetbrains intellij Idea |
|
| Vendors & Products |
Jetbrains
Jetbrains intellij Idea |
Thu, 23 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: JetBrains
Published:
Updated: 2026-07-24T03:56:18.148Z
Reserved: 2026-07-20T18:20:31.114Z
Link: CVE-2026-64815
Updated: 2026-07-23T13:20:22.719Z
Status : Analyzed
Published: 2026-07-23T12:18:37.120
Modified: 2026-07-28T17:11:02.603
Link: CVE-2026-64815
No data.
OpenCVE Enrichment
Updated: 2026-08-04T15:30:06Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')