PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75058 JetBrains CVE debrief

A medium-severity vulnerability was found in JetBrains IntelliJ IDEA before version 2026.2.1, where xXE was possible in the Eclipse settings importers. This issue has been addressed in the latest version. The vulnerability affects IntelliJ IDEA versions prior to 2026.2.1, and defenders should verify exposure and apply patches. The Eclipse settings importers are impacted, and a review of these importers is recommended to identify potential vulnerabilities. Additionally, monitoring for potential exploitation attempts is crucial. The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions.

Vendor
JetBrains
Product
IntelliJ IDEA
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-11
Advisory published
2026-08-17
Advisory updated
2026-09-11

Who should care

Defenders and administrators using JetBrains IntelliJ IDEA versions prior to 2026.2.1 should verify exposure and apply patches. The vulnerability affects IntelliJ IDEA versions prior to 2026.2.1, and defenders should review Eclipse settings importers for potential vulnerabilities and monitor for potential exploitation attempts.

Why it matters

A medium-severity vulnerability was found in JetBrains IntelliJ IDEA before version 2026.2.1, where xXE was possible in the Eclipse settings importers. Defenders should prioritize verifying exposure and applying patches.

  • Verify exposure and apply patches for IntelliJ IDEA versions prior to 2026.2.1
  • Review Eclipse settings importers for potential vulnerabilities
  • Monitor for potential exploitation attempts

Technical summary

A medium-severity vulnerability was found in JetBrains IntelliJ IDEA before version 2026.2.1, where xXE was possible in the Eclipse settings importers. The vulnerability affects IntelliJ IDEA versions prior to 2026.2.1. The issue has been addressed in the latest version. Defenders should prioritize verifying exposure and applying patches. The Eclipse settings importers are impacted, and a review of these importers is recommended to identify potential vulnerabilities.

Defensive priority

Defenders should prioritize verifying exposure and applying patches for IntelliJ IDEA versions prior to 2026.2.1.

Recommended defensive actions

  • Verify IntelliJ IDEA version and apply patches if necessary
  • Review Eclipse settings importers for potential vulnerabilities
  • Monitor for potential exploitation attempts

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions. The evidence is limited, and defenders should verify exposure and apply patches for IntelliJ IDEA versions prior to 2026.2.1. The Eclipse settings importers are impacted, and a review of these importers is recommended to identify potential vulnerabilities.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75058 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75058

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75058 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75058

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.