XML External Entity injection in IntelliJ IDEA - CVE-2026-75058
Published: August 17, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to xml external entity resolution in Eclipse settings importers when parsing imported settings files. A local user can supply a specially crafted settings file to disclose sensitive information.
User interaction is required to import a crafted settings file.