PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75055 JetBrains CVE debrief

A vulnerability in JetBrains IntelliJ IDEA before version 2026.2.1 allows the Hadoop ResourceManager to read local files via an XML External Entity (XXE) attack. This issue, tracked as CVE-2026-75055, has a CVSS score of 5.5 and is classified as medium severity. The vulnerability can lead to potential unauthorized file reads, and defenders should prioritize verifying exposure and applying patches to prevent this. The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions.

Vendor
JetBrains
Product
IntelliJ IDEA
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-11
Advisory published
2026-08-17
Advisory updated
2026-09-11

Who should care

Defenders and administrators responsible for IntelliJ IDEA deployments, particularly those using Hadoop ResourceManager, should assess exposure and apply patches if necessary.

Why it matters

CVE-2026-75055 is a medium-severity XXE vulnerability in JetBrains IntelliJ IDEA before version 2026.2.1, affecting the Hadoop ResourceManager. Defenders should prioritize verifying exposure and applying patches to prevent potential unauthorized file reads.

  • Potential unauthorized file reads via XXE attacks
  • Need to verify exposure and apply patches for affected versions
  • Possible impact on systems with Hadoop ResourceManager access

Technical summary

CVE-2026-75055 is an XXE vulnerability in JetBrains IntelliJ IDEA before version 2026.2.1, allowing the Hadoop ResourceManager to read local files. The vulnerability has a CVSS score of 5.5 and is classified as medium severity. It affects the Hadoop ResourceManager component, and defenders should focus on verifying exposure and applying patches for affected versions, particularly those with Hadoop ResourceManager access.

Defensive priority

Defenders should prioritize verifying exposure and applying patches for IntelliJ IDEA versions prior to 2026.2.1, focusing on systems with Hadoop ResourceManager access.

Recommended defensive actions

  • Verify IntelliJ IDEA version and apply patches if necessary
  • Review Hadoop ResourceManager access controls
  • Monitor for potential file reads via XXE attacks

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions. Vendor advisory information is also available.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75055 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75055

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75055 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75055

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.