CVE-2026-64808

JetBrains · PhpStorm

An inclusion of functionality from an untrusted control sphere (CWE-829) in JetBrains PhpStorm allows for potential unauthorized system compromise.

Executive summary

A high-severity vulnerability in JetBrains PhpStorm, rated 8.4, could allow an attacker to achieve total system impact through the inclusion of untrusted components.

Vulnerability

The software is susceptible to CWE-829, which involves the inclusion of functionality from an untrusted control sphere. This vulnerability is accessible to an unauthenticated attacker, although it requires local access (AV:L) to the system environment to trigger.

Business impact

The CVSS score of 8.4 reflects a high risk to the confidentiality, integrity, and availability of the development environment. If exploited, an attacker could gain elevated control over the local system, potentially leading to the theft of source code, credentials, or the injection of malicious code into development pipelines.

Remediation

Immediate Action: Update JetBrains PhpStorm to version 2026.2 or later immediately to resolve the identified security deficiency.

Proactive Monitoring: Review local system logs for unauthorized file access or anomalous process execution within the PhpStorm environment.

Compensating Controls: Ensure that the host operating system is hardened and that file system permissions are strictly enforced to prevent unauthorized modification of application components.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for total impact, all users should update their PhpStorm installations to the latest version. Organizations should treat this as a high-priority update to protect sensitive development assets.