Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ |
|
Tue, 08 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Sep 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Missing Authentication Exposes Profiling Data in JetBrains GoLand Profiler | |
| First Time appeared |
Jetbrains
Jetbrains goland |
|
| Vendors & Products |
Jetbrains
Jetbrains goland |
Mon, 07 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: JetBrains
Published:
Updated: 2026-09-08T10:34:59.970Z
Reserved: 2026-09-07T16:13:41.786Z
Link: CVE-2026-86506
Updated: 2026-09-08T10:32:38.127Z
Status : Awaiting Analysis
Published: 2026-09-07T17:17:29.130
Modified: 2026-09-08T15:32:32.217
Link: CVE-2026-86506
No data.
OpenCVE Enrichment
Updated: 2026-09-07T17:45:17Z
-
CWE-306
Missing Authentication for Critical Function