Known Vulnerabilities for Teamcity by Jetbrains
Listed below are 10 of the newest known vulnerabilities associated with "Teamcity" by "Jetbrains".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65907 json | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-65906 json | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | Not Provided | 2026-07-23 | 2026-07-24 |
| CVE-2026-63077 json | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling pro... | Not Provided | 2026-07-27 | 2026-07-28 |
| CVE-2026-59796 json | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-59795 json | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-59794 json | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-59793 json | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-49381 json | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible | Not Provided | 2026-05-29 | 2026-05-29 |
| CVE-2026-49380 json | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible | Not Provided | 2026-05-29 | 2026-05-29 |
| CVE-2026-49379 json | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names | Not Provided | 2026-05-29 | 2026-05-29 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Jetbrains | Teamcity | 9.1 | |||
| Application | Jetbrains | Teamcity | 9.0 | |||
| Application | Jetbrains | Teamcity | 8.1 | |||
| Application | Jetbrains | Teamcity | 8.0 | |||
| Application | Jetbrains | Teamcity | 7.1 | |||
| Application | Jetbrains | Teamcity | 7.0 | |||
| Application | Jetbrains | Teamcity | 6.5 | |||
| Application | Jetbrains | Teamcity | 6.0 | |||
| Application | Jetbrains | Teamcity | 5.1 | |||
| Application | Jetbrains | Teamcity | 5.0 | |||
| Application | Jetbrains | Teamcity | 4.5 | |||
| Application | Jetbrains | Teamcity | 4.0.2 | |||
| Application | Jetbrains | Teamcity | 4.0.1 | |||
| Application | Jetbrains | Teamcity | 4.0 | |||
| Application | Jetbrains | Teamcity | 3.1 | |||
| Application | Jetbrains | Teamcity | 3.0 | |||
| Application | Jetbrains | Teamcity | 2020.2.85695 | |||
| Application | Jetbrains | Teamcity | 2020.2.2 | |||
| Application | Jetbrains | Teamcity | 2020.2.1 | |||
| Application | Jetbrains | Teamcity | 2020.2 |