
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75054 is a Server-Side Request Forgery (SSRF) vulnerability in JetBrains IntelliJ IDEA affecting all versions before 2026.2.1. The flaw exists in the OpenAPI preview proxy feature and can be triggered when a user opens an untrusted project. It was published on August 17, 2026, with a CVSS v3.1 base score of 6.3 (Medium) (GitHub Advisory, JetBrains).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where the OpenAPI preview proxy in IntelliJ IDEA fails to sufficiently validate or restrict URLs it fetches on behalf of the user. An attacker can craft a malicious project file that, when opened by a victim, causes the IDE's proxy to issue HTTP requests to arbitrary internal or external network destinations. The attack vector is local, requires no privileges, but does require user interaction (opening the untrusted project), and the scope is changed — meaning the SSRF can reach resources outside the IDE's immediate security boundary (GitHub Advisory).
Successful exploitation allows an attacker to leverage the victim's IntelliJ IDEA instance as a proxy to access internal network resources and services not directly reachable from the attacker's position, resulting in high confidentiality impact. This could expose sensitive internal APIs, metadata services (e.g., cloud instance metadata endpoints), or other intranet services. There is no integrity or availability impact associated with this vulnerability (GitHub Advisory, JetBrains).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable, as it requires a user to manually open a malicious project file.
http://169.254.169.254/latest/meta-data/ for cloud metadata, or an internal service endpoint).169.254.169.254) originating from the IntelliJ IDEA process.idea.exe or idea process) initiating network connections to unusual internal hosts or services not typically accessed during normal IDE operation.JetBrains has released IntelliJ IDEA version 2026.2.1, which resolves this vulnerability. Users should upgrade to version 2026.2.1 or later as the primary remediation (JetBrains, GitHub Advisory). As a workaround, avoid opening projects from untrusted or unknown sources. Additionally, consider restricting IntelliJ IDEA's network access at the host firewall or endpoint security level to limit the potential reach of any SSRF exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."