Known Vulnerabilities for IntelliJ IDEA by JetBrains
Listed below are 10 of the newest known vulnerabilities associated with "IntelliJ IDEA" by "JetBrains".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-75058 json | In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75057 json | In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75056 json | In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-75055 json | In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75054 json | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75053 json | In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-75052 json | In JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted pro... | Not Provided | 2026-08-17 | 2026-08-17 |
| CVE-2026-64815 json | In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-64814 json | In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session | Not Provided | 2026-07-23 | 2026-07-23 |
| CVE-2026-64813 json | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | Not Provided | 2026-07-23 | 2026-07-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jetbrains | Intellij Idea | 9.0.4 | |||
| Application | Jetbrains | Intellij Idea | 9.0.3 | |||
| Application | Jetbrains | Intellij Idea | 2020.3 | |||
| Application | Jetbrains | Intellij Idea | 2020.2 | |||
| Application | Jetbrains | Intellij Idea | 2020.1 | |||
| Application | Jetbrains | Intellij Idea | 2019.3.4 | |||
| Application | Jetbrains | Intellij Idea | 2019.3.3 | |||
| Application | Jetbrains | Intellij Idea | 2019.3.0 | |||
| Application | Jetbrains | Intellij Idea | 2019.3 | |||
| Application | Jetbrains | Intellij Idea | 2019.2.4 | |||
| Application | Jetbrains | Intellij Idea | 2019.2.3 | |||
| Application | Jetbrains | Intellij Idea | 2019.2.2 | |||
| Application | Jetbrains | Intellij Idea | 2019.2.1 | |||
| Application | Jetbrains | Intellij Idea | 2019.2 | |||
| Application | Jetbrains | Intellij Idea | 2019.1.4 | |||
| Application | Jetbrains | Intellij Idea | 2019.1.3 | |||
| Application | Jetbrains | Intellij Idea | 2019.1.2 | |||
| Application | Jetbrains | Intellij Idea | 2019.1.1 | |||
| Application | Jetbrains | Intellij Idea | 2019.1 | |||
| Application | Jetbrains | Intellij Idea | 2018.3.6 |