PatchSiren cyber security CVE debrief
CVE-2026-75058 JetBrains CVE debrief
A medium-severity vulnerability was found in JetBrains IntelliJ IDEA before version 2026.2.1, where xXE was possible in the Eclipse settings importers. This issue has been addressed in the latest version. The vulnerability affects IntelliJ IDEA versions prior to 2026.2.1, and defenders should verify exposure and apply patches. The Eclipse settings importers are impacted, and a review of these importers is recommended to identify potential vulnerabilities. Additionally, monitoring for potential exploitation attempts is crucial. The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions.
- Vendor
- JetBrains
- Product
- IntelliJ IDEA
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-11
Who should care
Defenders and administrators using JetBrains IntelliJ IDEA versions prior to 2026.2.1 should verify exposure and apply patches. The vulnerability affects IntelliJ IDEA versions prior to 2026.2.1, and defenders should review Eclipse settings importers for potential vulnerabilities and monitor for potential exploitation attempts.
Why it matters
A medium-severity vulnerability was found in JetBrains IntelliJ IDEA before version 2026.2.1, where xXE was possible in the Eclipse settings importers. Defenders should prioritize verifying exposure and applying patches.
- Verify exposure and apply patches for IntelliJ IDEA versions prior to 2026.2.1
- Review Eclipse settings importers for potential vulnerabilities
- Monitor for potential exploitation attempts
Technical summary
A medium-severity vulnerability was found in JetBrains IntelliJ IDEA before version 2026.2.1, where xXE was possible in the Eclipse settings importers. The vulnerability affects IntelliJ IDEA versions prior to 2026.2.1. The issue has been addressed in the latest version. Defenders should prioritize verifying exposure and applying patches. The Eclipse settings importers are impacted, and a review of these importers is recommended to identify potential vulnerabilities.
Defensive priority
Defenders should prioritize verifying exposure and applying patches for IntelliJ IDEA versions prior to 2026.2.1.
Recommended defensive actions
- Verify IntelliJ IDEA version and apply patches if necessary
- Review Eclipse settings importers for potential vulnerabilities
- Monitor for potential exploitation attempts
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions. The evidence is limited, and defenders should verify exposure and apply patches for IntelliJ IDEA versions prior to 2026.2.1. The Eclipse settings importers are impacted, and a review of these importers is recommended to identify potential vulnerabilities.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75058 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75058
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75058 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75058
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.jetbrains.com/privacy-security/issues-fixed/
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.