Description
In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
Published: 2026-08-17
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exposes JetBrains IntelliJ IDEA to server‑side request forgery (SSRF) via the OpenAPI preview proxy when the IDE processes untrusted project files. Attackers could potentially instruct the IDE to perform arbitrary HTTP requests from the host machine, leaking internal secrets or facilitating further network attacks. The weakness is classified as CWE‑918, indicating the improper validation of URLs before performing outbound network requests. The effect is a compromise of confidentiality and integrity for the machine running the IDE, and could be a stepping stone for more severe exploits.

Affected Systems

JetBrains IntelliJ IDEA versions prior to 2026.2.1 are affected. Only the JetBrains product is implicated; later releases include the fix.

Risk and Exploitability

The CVSS score of 6.3 marks it as high‑severity, while the EPSS score is currently unavailable but the issue is not listed in KEV. The attack vector is inferred to be Local or Remote depending on how untrusted project files are introduced, with no active exploits noted. The risk is moderate to high, especially for environments that routinely import untrusted projects or expose the IDE to networked clients.

Generated by OpenCVE AI on August 17, 2026 at 17:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade IntelliJ IDEA to version 2026.2.1 or later to eliminate the SSRF flaw.
  • If an upgrade is not immediately possible, restrict the import of untrusted projects to authorized users only.
  • Disable or configure the OpenAPI preview proxy feature to limit outbound network requests from the IDE.

Generated by OpenCVE AI on August 17, 2026 at 17:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Server‑side request forgery via OpenAPI preview proxy in JetBrains IntelliJ IDEA

Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains intellij Idea
Vendors & Products Jetbrains
Jetbrains intellij Idea

Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

Jetbrains Intellij Idea
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-08-17T18:32:49.515Z

Reserved: 2026-08-17T15:34:09.708Z

Link: CVE-2026-75054

cve-icon Vulnrichment

Updated: 2026-08-17T18:32:35.940Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-17T16:17:52.543

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-75054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T18:00:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)