Impact
In JetBrains IntelliJ IDEA older than 2026.2.1, the Eclipse settings importer processes XML data that may contain malicious external entity references. The vulnerability allows an attacker to supply a crafted Eclipse XML file that forces the importer to resolve external entities. If the attacker controls the entity target, the importer can read arbitrary files from the local filesystem or download external data, potentially leading to information disclosure.
Affected Systems
JetBrains IntelliJ IDEA versions before 2026.2.1 are affected. The issue arises when using the Eclipse settings importer in these releases. No specific sub‑product or operating system restrictions are listed in the CNA data.
Risk and Exploitability
The CVSS score is 5.5, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires a local user to import a malicious Eclipse settings file (inferred) or an attacker who can supply a file to the import process (inferred). Because the flaw is a classic XXE, exploitation is relatively straightforward for an attacker with the ability to supply the XML input. The risk is moderate; mitigation is recommended.
OpenCVE Enrichment