Sceawere

Vulnerability Detail

CVE-2026-75053UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

JetBrains IntelliJ IDEA DevKit SSRF

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
5h ago
Vendor
JetBrains
Product
IntelliJ IDEA
Attack Type
CWE-918
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-08-17T16:17:52.430Z",
  "pubdate": "2026-08-17T16:17:52.430Z",
  "executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in JetBrains IntelliJ IDEA prior to version 2026.2.1.\nThe vulnerability resides within the DevKit debug listener endpoint, allowing unauthorized request routing through the application.\nImpact includes potential unauthorized access to internal network resources, metadata services, and local infrastructure that are otherwise inaccessible from external networks.\nThe affected product is JetBrains IntelliJ IDEA, specifically deployments running vulnerable versions before 2026.2.1.\nRisk implications involve unauthorized data exposure, potential interaction with internal APIs, and service enumeration within the hosting environment.\nAttacker capabilities require the ability to interact with the target instance or trick the application into processing malicious payloads directed at the vulnerable listener endpoint.\nExploitation relies on the presence of the DevKit component exposing an inadequately restricted debug listener capable of initiating outbound connections based on unvalidated input.",
  "technicalDetails": "The vulnerability is classified as Server-Side Request Forgery (SSRF), stemming from insufficient validation and sanitization of user-supplied input handled by the DevKit debug listener endpoint within JetBrains IntelliJ IDEA.\nThe vulnerable component is the DevKit plugin subsystem, specifically its internal debug listener functionality responsible for handling incoming debugging or diagnostic connections.\nAffected versions include all instances of JetBrains IntelliJ IDEA prior to 2026.2.1.\nNetwork exposure typically involves listening interfaces associated with debugging services, which may be accessible locally or exposed depending on configuration settings.\nAuthentication and privilege requirements depend on local access vectors or network reachability to the debug listener endpoint, though unauthorized interaction is facilitated by the absence of strict access controls on the vulnerable handler.\nThe attack flow proceeds as follows: 1. The attacker crafts a malicious request targeting the DevKit debug listener endpoint within IntelliJ IDEA. 2. The listener parses the input without proper validation of destination parameters or URLs. 3. The underlying service initiates an outbound network connection to a specified target, which can be an internal resource, local network service, or external destination controlled by the attacker. 4. The application processes the response or facilitates data transit, allowing the attacker to interact with restricted internal endpoints via the vulnerable application context.\nPayload behavior involves manipulating connection parameters within the debug listener protocol or API calls to force the application to act as a proxy or traffic initiator.\nPost-exploitation impact includes internal network reconnaissance, unauthorized interaction with internal microservices, access to sensitive metadata endpoints, and potential data exfiltration mediated by the vulnerable server."
}
CVE-2026-75053: JetBrains IntelliJ IDEA DevKit SSRF (MEDIUM Severity, CVSS: 5.4) - Sceawere