CVE-2026-64806

JetBrains · WebStorm

A vulnerability in JetBrains WebStorm allows for potential unauthorized access or system compromise due to improper inclusion of control functionality.

Executive summary

A high-severity vulnerability in JetBrains WebStorm versions prior to 2026.2 exposes the application to potential compromise of confidentiality, integrity, and availability.

Vulnerability

This is an inclusion of functionality from an untrusted control sphere (CWE-829). The vulnerability can be exploited by an unauthenticated local attacker to achieve full system impact.

Business impact

The vulnerability carries a CVSS score of 8.4, which indicates a high risk to business operations. Successful exploitation could allow an attacker to gain unauthorized access to the local development environment, potentially leading to the theft of proprietary source code, credentials, or the execution of arbitrary code with the privileges of the user running the software.

Remediation

Immediate Action: Update JetBrains WebStorm to version 2026.2 or later immediately to resolve this security flaw.

Proactive Monitoring: Review system logs for unauthorized access or unusual process execution within the development environment.

Compensating Controls: Ensure that the local system is protected by endpoint security solutions and restrict local access to authorized users only.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the severity of this vulnerability, it is imperative that organizations using JetBrains WebStorm prioritize the upgrade to version 2026.2. Failure to patch may expose development environments to significant security risks.