CVE-2026-49383: XEE
Published May 29, 2026
·Updated
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
Affected Software
2 affected components
JetBrains IntelliJ IDEA<2026.1
JetBrains IntelliJ IDEA<2026.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains IntelliJ IDEAto a version that resolves this vulnerability.Fixed in 2026.1
Event History
May 29, 2026
CVE Published
via MITRE·06:15 PM
Data Sourced
via MITRE·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-49383?
The severity of CVE-2026-49383 is rated as low, with a score of 3.3.
2
What vulnerability does CVE-2026-49383 describe?
CVE-2026-49383 describes an XML External Entity (XEE) vulnerability in the UI Designer form parser of JetBrains IntelliJ IDEA.
3
How do I fix CVE-2026-49383?
To fix CVE-2026-49383, update JetBrains IntelliJ IDEA to version 2026.1 or later.
4
What is the impact of CVE-2026-49383 on my system?
The impact of CVE-2026-49383 is low, primarily affecting the user interface component without compromising integrity or availability.
5
Which versions of JetBrains IntelliJ IDEA are affected by CVE-2026-49383?
CVE-2026-49383 affects versions of JetBrains IntelliJ IDEA prior to 2026.1.