JetBrains / TeamCity
275 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-100255 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | HIGH | 8.1 | Sep 30, 2026 |
| CVE-2026-100254 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git conne… | HIGH | 8.8 | Sep 30, 2026 |
| CVE-2026-100253 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL | HIGH | 8.8 | Sep 30, 2026 |
| CVE-2026-63077 KEV | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | CRITICAL | 9.8 | Jul 27, 2026 |
| CVE-2026-65907 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible | CRITICAL | 9.1 | Jul 23, 2026 |
| CVE-2026-65906 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible | CRITICAL | 10.0 | Jul 23, 2026 |
| CVE-2026-59796 | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks | HIGH | 8.1 | Jul 10, 2026 |
| CVE-2026-59795 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible | HIGH | 8.1 | Jul 10, 2026 |
| CVE-2026-59794 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data | HIGH | 7.3 | Jul 10, 2026 |
| CVE-2026-59793 | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration | HIGH | 8.8 | Jul 10, 2026 |
| CVE-2026-49381 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible | MEDIUM | 4.8 | May 29, 2026 |
| CVE-2026-49380 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible | MEDIUM | 6.1 | May 29, 2026 |
| CVE-2026-49379 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names | MEDIUM | 6.5 | May 29, 2026 |
| CVE-2026-49378 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion | MEDIUM | 4.3 | May 29, 2026 |
| CVE-2026-49377 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters | MEDIUM | 4.3 | May 29, 2026 |
| CVE-2026-49376 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin | MEDIUM | 6.5 | May 29, 2026 |
| CVE-2026-49375 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page | MEDIUM | 6.1 | May 29, 2026 |
| CVE-2026-49374 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters | HIGH | 7.6 | May 29, 2026 |
| CVE-2026-49373 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings | HIGH | 8.8 | May 29, 2026 |
| CVE-2026-49372 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible | HIGH | 7.5 | May 29, 2026 |
| CVE-2026-49371 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible | HIGH | 8.2 | May 29, 2026 |
| CVE-2026-44413 | In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access | HIGH | 8.2 | May 11, 2026 |
| CVE-2026-28196 | In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk | LOW | 2.3 | Feb 25, 2026 |
| CVE-2026-28195 | In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations | MEDIUM | 4.3 | Feb 25, 2026 |
| CVE-2026-28194 | In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow | MEDIUM | 6.1 | Feb 25, 2026 |
Showing 1 to 25 of 275 CVEs