CVE-2026-75057
JetBrains IntelliJ IDEA vulnerability analysis and mitigation

Overview

CVE-2026-75057 is a sensitive information disclosure vulnerability in JetBrains IntelliJ IDEA where Git credentials are written in plaintext to the IDE log files. It affects all versions of IntelliJ IDEA before 2026.1.5 and was published on August 17, 2026. The vulnerability carries a CVSS v3.1 base score of 6.2 (Medium), reflecting its local attack vector and high confidentiality impact (GitHub Advisory, JetBrains).

Technical details

The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File): IntelliJ IDEA inadvertently writes Git credentials — such as usernames and passwords or tokens — in plaintext to its IDE log files during Git operations. Exploitation requires local access to the system where IntelliJ IDEA is installed, as an attacker must be able to read the IDE log files (typically located in the IDE's log directory). No authentication or user interaction is required beyond having local filesystem read access to the log directory (GitHub Advisory, JetBrains).

Impact

Successful exploitation allows a local attacker to extract plaintext Git credentials from IntelliJ IDEA log files, potentially compromising access to source code repositories. This could lead to unauthorized repository access, code theft, supply chain attacks, or injection of malicious code into repositories. Integrity and availability of the affected system are not directly impacted, but the confidentiality of Git credentials is fully compromised (GitHub Advisory).

Exploitability

There is currently no evidence of in-the-wild exploitation, and no public proof-of-concept exploit code has been identified. The NVD SSVC assessment indicates exploitation is "none" and the vulnerability is not automatable. The EPSS score is 0.0, reflecting a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Exploitation steps

  1. Gain local access: Obtain local user-level access to a system running a vulnerable version of JetBrains IntelliJ IDEA (before 2026.1.5), either through physical access, a compromised account, or another vulnerability.
  2. Locate IDE log files: Navigate to the IntelliJ IDEA log directory, typically found at ~/.cache/JetBrains/IntelliJIdea<version>/log/idea.log on Linux, ~/Library/Logs/JetBrains/IntelliJIdea<version>/idea.log on macOS, or %APPDATA%\JetBrains\IntelliJIdea<version>\log\idea.log on Windows.
  3. Search for credentials: Use tools such as grep, findstr, or a text editor to search the log file for keywords like password, credential, token, Authorization, or Git remote URLs that may contain embedded credentials.
  4. Extract and use credentials: Collect the plaintext Git credentials found in the logs and use them to authenticate to the corresponding Git repositories (e.g., GitHub, GitLab, Bitbucket) for unauthorized access, data exfiltration, or code manipulation (GitHub Advisory).

Indicators of compromise

  • File System: Unexpected access or reads of IntelliJ IDEA log files (idea.log) by processes or users other than the IDE itself; log files copied or exfiltrated to unusual locations.
  • Logs: Audit logs showing unauthorized access to the IDE log directory (e.g., ~/.cache/JetBrains/, %APPDATA%\JetBrains\) by non-IDE processes or unexpected user accounts.
  • Network: Unusual authentication attempts to Git hosting services (GitHub, GitLab, Bitbucket) from unexpected IP addresses or at unusual times, potentially indicating credential reuse after extraction.

Mitigation and workarounds

JetBrains has released a fix in IntelliJ IDEA version 2026.1.5, which prevents Git credentials from being written to the IDE log. Users should upgrade to version 2026.1.5 or later as the primary remediation. As a temporary workaround prior to upgrading, users should restrict filesystem permissions on the IntelliJ IDEA log directory to prevent unauthorized read access, and consider rotating any Git credentials that may have been exposed in logs on affected versions (JetBrains, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JetBrains IntelliJ IDEA vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75056HIGH7.8
  • JetBrains IntelliJ IDEA logoJetBrains IntelliJ IDEA
  • cpe:2.3:a:jetbrains:intellij_idea
NoYesAug 17, 2026
CVE-2026-75054MEDIUM6.3
  • JetBrains IntelliJ IDEA logoJetBrains IntelliJ IDEA
  • cpe:2.3:a:jetbrains:intellij_idea
NoYesAug 17, 2026
CVE-2026-75057MEDIUM6.2
  • JetBrains IntelliJ IDEA logoJetBrains IntelliJ IDEA
  • cpe:2.3:a:jetbrains:intellij_idea
NoYesAug 17, 2026
CVE-2026-75058MEDIUM5.5
  • JetBrains IntelliJ IDEA logoJetBrains IntelliJ IDEA
  • cpe:2.3:a:jetbrains:intellij_idea
NoYesAug 17, 2026
CVE-2026-75055MEDIUM5.5
  • JetBrains IntelliJ IDEA logoJetBrains IntelliJ IDEA
  • cpe:2.3:a:jetbrains:intellij_idea
NoYesAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management