PatchSiren cyber security CVE debrief
CVE-2026-75055 JetBrains CVE debrief
A vulnerability in JetBrains IntelliJ IDEA before version 2026.2.1 allows the Hadoop ResourceManager to read local files via an XML External Entity (XXE) attack. This issue, tracked as CVE-2026-75055, has a CVSS score of 5.5 and is classified as medium severity. The vulnerability can lead to potential unauthorized file reads, and defenders should prioritize verifying exposure and applying patches to prevent this. The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions.
- Vendor
- JetBrains
- Product
- IntelliJ IDEA
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-11
Who should care
Defenders and administrators responsible for IntelliJ IDEA deployments, particularly those using Hadoop ResourceManager, should assess exposure and apply patches if necessary.
Why it matters
CVE-2026-75055 is a medium-severity XXE vulnerability in JetBrains IntelliJ IDEA before version 2026.2.1, affecting the Hadoop ResourceManager. Defenders should prioritize verifying exposure and applying patches to prevent potential unauthorized file reads.
- Potential unauthorized file reads via XXE attacks
- Need to verify exposure and apply patches for affected versions
- Possible impact on systems with Hadoop ResourceManager access
Technical summary
CVE-2026-75055 is an XXE vulnerability in JetBrains IntelliJ IDEA before version 2026.2.1, allowing the Hadoop ResourceManager to read local files. The vulnerability has a CVSS score of 5.5 and is classified as medium severity. It affects the Hadoop ResourceManager component, and defenders should focus on verifying exposure and applying patches for affected versions, particularly those with Hadoop ResourceManager access.
Defensive priority
Defenders should prioritize verifying exposure and applying patches for IntelliJ IDEA versions prior to 2026.2.1, focusing on systems with Hadoop ResourceManager access.
Recommended defensive actions
- Verify IntelliJ IDEA version and apply patches if necessary
- Review Hadoop ResourceManager access controls
- Monitor for potential file reads via XXE attacks
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions. Vendor advisory information is also available.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75055 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75055
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75055 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75055
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jetbrains.com/privacy-security/issues-fixed/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.