CVE-2026-86506

In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data

  • Published Sep 7, 2026
  • CVSS 5.9 medium
  • 0.4% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-86506 at the National Vulnerability Database