CVE-2026-86504
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execut
CVSS
7.8
Alto
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 7 sept 2026 · Última mod.: 8 sept 2026 · CWE-829
Sin historial EPSS suficiente todavía.
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-861698.8 ALT39.9%
——12Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python code by crafting a malicious Hugging Face model repository selected as base_model, which is loaded with hardcoded trust_remote_code=True during AutoModelForCausalLM.from_pretrained.3dCVE-2026-825255.5 MED3.8%
——1Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled XSLT stylesheets within a Report.xml file inside a UFDR ZIP evidence item. Attackers can craft a malicious UFDR archive that, when previewed by an examiner, causes the XML parser to resolve file:// external entity references and execute msxsl:script within the external stylesheet to exfiltrate the resolved file contents to an attacker-controlled endpoint via a generated image URL.5dCVE-2026-585698.8 ALT2.8%
——1Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..4dCVE-2026-182527.3 ALT25.8%
——8GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.8dCVE-2026-761398.0 ALT37.4%
——11A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting operator bundle.4hCVE-2026-2230610.0 CRÍ5.8%
——2Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext
transmission of sensitive information vulnerability in Ozols Grupa OZOLS
on Windows caused by an abandoned auto-update domain. Affected
component: the automatic update channel - OzolsSQL client update path, the <db>_update SQL Server Agent job (@subsystem = N'ActiveScripting') and serv_update.vbs.
This issue affects OZOLS: before 1.1.1233.7d