Cross-Site Scripting in JetBrains IntelliJ IDEA Eclipse Settings Importer
CVE-2026-75058

5.5MEDIUM

Key Information:

Vendor

Jetbrains

Vendor
CVE Published:
17 August 2026

What is CVE-2026-75058?

A cross-site scripting vulnerability exists in JetBrains IntelliJ IDEA, specifically affecting the import process of Eclipse settings. This flaw allows an attacker to inject malicious scripts into the application, which could be executed in the context of the user’s session, potentially leading to unauthorized actions or data exposure. It is essential for users of affected versions to update their software to mitigate potential risks.

Affected Version(s)

IntelliJ IDEA 0 < 2026.2.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.