CVE-2026-64808
JetBrains · PhpStorm
An inclusion of functionality from an untrusted control sphere (CWE-829) in JetBrains PhpStorm allows for potential unauthorized system compromise.
Executive summary
A high-severity vulnerability in JetBrains PhpStorm, rated 8.4, could allow an attacker to achieve total system impact through the inclusion of untrusted components.
Vulnerability
The software is susceptible to CWE-829, which involves the inclusion of functionality from an untrusted control sphere. This vulnerability is accessible to an unauthenticated attacker, although it requires local access (AV:L) to the system environment to trigger.
Business impact
The CVSS score of 8.4 reflects a high risk to the confidentiality, integrity, and availability of the development environment. If exploited, an attacker could gain elevated control over the local system, potentially leading to the theft of source code, credentials, or the injection of malicious code into development pipelines.
Remediation
Immediate Action: Update JetBrains PhpStorm to version 2026.2 or later immediately to resolve the identified security deficiency.
Proactive Monitoring: Review local system logs for unauthorized file access or anomalous process execution within the PhpStorm environment.
Compensating Controls: Ensure that the host operating system is hardened and that file system permissions are strictly enforced to prevent unauthorized modification of application components.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for total impact, all users should update their PhpStorm installations to the latest version. Organizations should treat this as a high-priority update to protect sensitive development assets.