XXE Vulnerability in JetBrains IntelliJ IDEA Affecting ResourceManager
CVE-2026-75055

5.5MEDIUM

Key Information:

Vendor

Jetbrains

Vendor
CVE Published:
17 August 2026

What is CVE-2026-75055?

A vulnerability exists in JetBrains IntelliJ IDEA versions prior to 2026.2.1, allowing the ResourceManager to access local files through XML External Entity (XXE) injection. This flaw poses a risk of unauthorized data exposure and could lead to significant security issues if exploited. It's crucial for users to update their IntelliJ IDEA to mitigate this risk. For more details on security fixes, visit JetBrains' official page.

Affected Version(s)

IntelliJ IDEA 0 < 2026.2.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.