Sceawere

Vulnerability Detail

CVE-2026-75055UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IntelliJ IDEA Hadoop ResourceManager XXE

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
5h ago
Vendor
JetBrains
Product
IntelliJ IDEA
Attack Type
CWE-611
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-08-17T16:17:52.657Z",
  "pubdate": "2026-08-17T16:17:52.657Z",
  "executiveSummary": "A vulnerability exists in JetBrains IntelliJ IDEA before 2026.2.1 involving the hadoop ResourceManager component, which is susceptible to XML External Entity (XXE) injection.\nThis flaw allows unauthorized local file read operations through the processing of maliciously crafted XML inputs.\nThe vulnerability impacts the confidentiality of affected systems by enabling unauthorized actors to access sensitive local files accessible to the application process.\nExploitation of this vulnerability requires the parsing of untrusted XML data via the vulnerable hadoop ResourceManager component within the affected product.\nThe risk implication is significant as it potentially exposes critical system or application data to unauthorized entities without requiring advanced privileges, depending on the network exposure and integration context of the ResourceManager component.",
  "technicalDetails": "The vulnerability stems from insecure XML parser configurations within the hadoop ResourceManager component of JetBrains IntelliJ IDEA before 2026.2.1.\nSpecifically, the XML parsing mechanism fails to appropriately disable the resolution of external entities and external DTDs (Document Type Definitions) when processing untrusted input streams.\nThis architectural oversight leads directly to an XML External Entity (XXE) injection vulnerability, allowing an attacker to define custom external entities referencing local file paths using supported URI schemes.\nThe attack flow initiates when a malicious XML payload containing crafted external entity definitions is submitted to the vulnerable hadoop ResourceManager component.\nUpon receiving the payload, the underlying XML parser attempts to resolve and evaluate the external entities during the document parsing phase.\nDuring entity resolution, the application reads the targeted local file from the underlying filesystem based on the URI provided in the payload.\nThe retrieved file contents can then be embedded into the application response or leveraged via out-of-band data exfiltration channels, depending on the specific parser configuration and network connectivity.\nThe vulnerable component is the hadoop ResourceManager integrated within JetBrains IntelliJ IDEA prior to version 2026.2.1.\nNetwork exposure and authentication requirements depend on how the ResourceManager component is exposed and utilized within the specific development environment or deployment configuration.\nSuccessful exploitation results in the unauthorized disclosure of local files readable by the process context executing the application, undermining the confidentiality boundary of the host system."
}
CVE-2026-75055: IntelliJ IDEA Hadoop ResourceManager XXE (MEDIUM Severity, CVSS: 5.5) - Sceawere