CVE-2026-64809
JetBrains · PhpStorm
JetBrains PhpStorm is susceptible to a vulnerability involving the inclusion of functionality from an untrusted control sphere, potentially leading to total system impact.
Executive summary
JetBrains PhpStorm contains a high-severity vulnerability, rated 8.4, that could permit an attacker to leverage untrusted components for malicious system-level access.
Vulnerability
This vulnerability is classified as CWE-829, where the application includes functionality from an untrusted source. It allows an unauthenticated local attacker to execute operations with the privileges of the application, resulting in total impact to the system.
Business impact
The CVSS score of 8.4 indicates that successful exploitation poses a severe threat to business operations, particularly within software development lifecycles. Compromise could result in the exfiltration of intellectual property, unauthorized modification of project files, or persistence within the developer workstation.
Remediation
Immediate Action: Upgrade to JetBrains PhpStorm version 2026.2 or later to ensure the inclusion of necessary security patches.
Proactive Monitoring: Monitor for unexpected changes to project configurations or unusual activity within the application directory.
Compensating Controls: Utilize endpoint detection and response (EDR) solutions to monitor for suspicious process behavior associated with the IDE.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Security teams must ensure that all instances of PhpStorm are updated to version 2026.2 or higher. This update is essential to mitigate the risk of unauthorized system-level operations initiated through untrusted component inclusion.