Skip to main content

Vendor/product archive

jetbrains / teamcity CVEs

Beta · best-effort

275 CVEs tagged to jetbrains / teamcity18 Critical, 41 High, 186 Medium, 30 Low, 0 Unrated.

CVE-2026-63077

Published Jul 27, 2026

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CVSS 9.8 · Critical
evidence mentions
15
Buzz score
72.7
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-65906

Published Jul 23, 2026

In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-59796

Published Jul 10, 2026

In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-59795

Published Jul 10, 2026

In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-59794

Published Jul 10, 2026

In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-59793

Published Jul 10, 2026

In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49381

Published May 29, 2026

In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible

CVSS 3.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49380

Published May 29, 2026

In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49379

Published May 29, 2026

In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49378

Published May 29, 2026

In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49377

Published May 29, 2026

In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49376

Published May 29, 2026

In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49375

Published May 29, 2026

In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49374

Published May 29, 2026

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49373

Published May 29, 2026

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49372

Published May 29, 2026

In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-49371

Published May 29, 2026

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44413

Published May 11, 2026

In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access

CVSS 8.2 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-28196

Published Feb 25, 2026

In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28195

Published Feb 25, 2026

In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28194

Published Feb 25, 2026

In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-68268

Published Dec 16, 2025

In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68267

Published Dec 16, 2025

In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-68166

Published Dec 16, 2025

In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 275 CVEsPage 1 of 11