Description
In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
Published: 2026-08-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Markdown export tool of JetBrains IntelliJ IDEA versions earlier than 2026.2.1. When a specially crafted Markdown document is processed, it can cause the IDE to execute arbitrary code, giving the attacker full control of the host system. This issue is classified as a remote code execution vulnerability.

Affected Systems

JetBrains IntelliJ IDEA users on any operating system running a version before 2026.2.1 are vulnerable. The affected builds are those identified as IntelliJ IDEA 2026.2 and earlier. No additional vendors or products are known to be impacted.

Risk and Exploitability

The CVSS base score of 7.8 indicates moderate to high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely leveraged in the wild. The attack appears to require the user to open a malicious Markdown file and invoke the export function, which may limit exploitation to users with sufficient access or through social engineering.

Generated by OpenCVE AI on August 17, 2026 at 17:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an update to IntelliJ IDEA 2026.2.1 or later to eliminate the flaw.
  • If an immediate update is not feasible, disable or avoid using the Markdown export feature until a patched version is available.
  • Verify that no older, vulnerable versions of IntelliJ IDEA remain installed on workstations or servers exposed to untrusted files.

Generated by OpenCVE AI on August 17, 2026 at 17:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Markdown Export Tool in IntelliJ IDEA

Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains intellij Idea
Vendors & Products Jetbrains
Jetbrains intellij Idea

Mon, 17 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Jetbrains Intellij Idea
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-08-18T03:55:38.767Z

Reserved: 2026-08-17T15:34:10.546Z

Link: CVE-2026-75056

cve-icon Vulnrichment

Updated: 2026-08-17T16:15:11.096Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-17T16:17:52.770

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-75056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T18:00:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')