CVE-2026-75058
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
CVSS
5.5
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 17, 2026 · Last modified: Aug 17, 2026 · CWE-611
Not enough EPSS history yet.
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-750555.5 MED—
——0In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE1dCVE-2026-691017.7 HIG27.0%
——8Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditWorkflow endpoint, which processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Attackers can send a malicious XML document containing an external DTD reference to the edit_workflow action, causing the server to issue outbound HTTP requests to attacker-controlled infrastructure and exfiltrate local files readable by the TIS process user, including configuration files and Derby database credentials.4dCVE-2026-187156.5 MED16.4%
——5IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external entities.2dCVE-2026-15803—27.3%
——8In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results, permitting DOCTYPE declarations, external entity references, and external DTD loading. This is due to an incomplete fix for CVE-2018-1000644: the earlier fix did not cover all parser entry points. The issue is resolved in RDF4J 5.3.2, which rejects or disables DOCTYPE declarations, external entities, and external DTD loading by default.11hCVE-2026-169996.3 MED2.9%
——1Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking.
This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.6dCVE-2026-732356.1 MED2.7%
——1FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp by Base::XMLReader::XMLReader() parses attacker-controlled Document.xml from a crafted .FCStd archive without disabling default external entity resolution or external DTD loading. When Document::restore() opens the document, external entities can read local files through the file URI scheme or initiate server-side requests through the http URI scheme, and resolved content can flow through the characters() callback. This issue is fixed in version 1.1.2.6d