SB20260817105 - Multiple vulnerabilities in IntelliJ IDEA



SB20260817105 - Multiple vulnerabilities in IntelliJ IDEA

Published: August 17, 2026

Security Bulletin ID SB20260817105
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 vulnerabilities.


1) XML External Entity injection (CVE-ID: CVE-2026-75058)

CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to xml external entity resolution in Eclipse settings importers when parsing imported settings files. A local user can supply a specially crafted settings file to disclose sensitive information.

User interaction is required to import a crafted settings file.


2) Command injection (CVE-ID: CVE-2026-75056)

CWE-ID: CWE-77 - Command injection

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to command injection in the Markdown export tool when exporting crafted markdown content. A remote user can supply specially crafted markdown content to execute arbitrary code.


3) XML External Entity injection (CVE-ID: CVE-2026-75055)

CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose local file contents.

The vulnerability exists due to XML external entity processing in Hadoop ResourceManager when parsing XML input. A remote attacker can supply a specially crafted XML payload to disclose local file contents.


4) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-75054)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to trigger server-side request forgery.

The vulnerability exists due to server-side request forgery in OpenAPI preview proxy when processing preview requests in untrusted projects. A remote user can supply a crafted target to cause the application to issue unintended requests.

Only untrusted projects are affected.


5) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-75053)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to initiate server-side request forgery.

The vulnerability exists due to server-side request forgery in DevKit debug listener endpoint when handling requests. A remote attacker can send a specially crafted request to initiate server-side request forgery.


6) Command injection (CVE-ID: CVE-2026-75052)

CWE-ID: CWE-77 - Command injection

CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary commands.

The vulnerability exists due to command injection in the Markdown preview component when rendering crafted Markdown content in a trusted project. A remote user can create crafted Markdown preview content to execute arbitrary commands.

Exploitation is possible only in trusted projects.


Remediation

Install update from vendor's website.