CVE-2026-75055
JetBrains IntelliJ IDEA vulnerability analysis and mitigation

Overview

CVE-2026-75055 is an XML External Entity (XXE) injection vulnerability in JetBrains IntelliJ IDEA's Hadoop ResourceManager integration that allows a local attacker to read arbitrary files on the affected system. It affects all versions of IntelliJ IDEA before 2026.2.1. The vulnerability was published on August 17, 2026, with a patch available in version 2026.2.1. It carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, JetBrains).

Technical details

The vulnerability is classified as CWE-611 (Improper Restriction of XML External Entity Reference), where the Hadoop ResourceManager component in IntelliJ IDEA fails to properly restrict the processing of XML external entities. An attacker can craft a malicious XML payload referencing local file URIs, which the application processes without adequate sanitization, resulting in disclosure of local file contents. Exploitation requires local access and user interaction — the victim must trigger the vulnerable XML parsing functionality within the IDE (GitHub Advisory, JetBrains).

Impact

Successful exploitation results in high confidentiality impact, allowing an attacker to read arbitrary local files accessible to the IntelliJ IDEA process — potentially including source code, configuration files, credentials, SSH keys, or other sensitive developer artifacts. There is no integrity or availability impact. The attack is limited to the local system where IntelliJ IDEA is running, with no scope change, reducing the risk of direct lateral movement (GitHub Advisory).

Exploitability

There is currently no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, as it requires user interaction to trigger the vulnerable code path. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory, JetBrains).

Mitigation and workarounds

The primary remediation is to update JetBrains IntelliJ IDEA to version 2026.2.1 or later, which contains the fix for this vulnerability. As interim mitigations, administrators should disable XML External Entity processing where configurable, restrict local file access permissions for the IntelliJ IDEA process to minimize exposure of sensitive files, and avoid opening untrusted Hadoop project configurations within the IDE (JetBrains, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JetBrains IntelliJ IDEA vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75056HIGH7.8
  • JetBrains IntelliJ IDEA logoJetBrains IntelliJ IDEA
  • cpe:2.3:a:jetbrains:intellij_idea
NoYesAug 17, 2026
CVE-2026-75054MEDIUM6.3
  • JetBrains IntelliJ IDEA logoJetBrains IntelliJ IDEA
  • cpe:2.3:a:jetbrains:intellij_idea
NoYesAug 17, 2026
CVE-2026-75057MEDIUM6.2
  • JetBrains IntelliJ IDEA logoJetBrains IntelliJ IDEA
  • cpe:2.3:a:jetbrains:intellij_idea
NoYesAug 17, 2026
CVE-2026-75058MEDIUM5.5
  • JetBrains IntelliJ IDEA logoJetBrains IntelliJ IDEA
  • cpe:2.3:a:jetbrains:intellij_idea
NoYesAug 17, 2026
CVE-2026-75055MEDIUM5.5
  • JetBrains IntelliJ IDEA logoJetBrains IntelliJ IDEA
  • cpe:2.3:a:jetbrains:intellij_idea
NoYesAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management