Vulnerabilities (CVE)

Filtered by vendor Jetbrains Subscribe
Filtered by product Teamcity
Total 275 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-65906 1 Jetbrains 1 Teamcity 2026-08-11 N/A 8.8 HIGH
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
CVE-2026-63077 1 Jetbrains 1 Teamcity 2026-08-06 N/A 9.8 CRITICAL
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
CVE-2026-49380 1 Jetbrains 1 Teamcity 2026-07-22 N/A 3.1 LOW
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
CVE-2026-49372 1 Jetbrains 1 Teamcity 2026-07-22 N/A 7.5 HIGH
In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
CVE-2026-49373 1 Jetbrains 1 Teamcity 2026-07-22 N/A 7.1 HIGH
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
CVE-2026-49374 1 Jetbrains 1 Teamcity 2026-07-22 N/A 7.6 HIGH
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
CVE-2026-49376 1 Jetbrains 1 Teamcity 2026-07-22 N/A 6.5 MEDIUM
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
CVE-2026-49375 1 Jetbrains 1 Teamcity 2026-07-22 N/A 6.1 MEDIUM
In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
CVE-2026-49377 1 Jetbrains 1 Teamcity 2026-07-22 N/A 4.3 MEDIUM
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
CVE-2026-49381 1 Jetbrains 1 Teamcity 2026-07-22 N/A 3.4 LOW
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
CVE-2026-49378 1 Jetbrains 1 Teamcity 2026-07-22 N/A 4.3 MEDIUM
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
CVE-2026-49371 1 Jetbrains 1 Teamcity 2026-07-22 N/A 7.1 HIGH
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
CVE-2026-49379 1 Jetbrains 1 Teamcity 2026-07-22 N/A 6.5 MEDIUM
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
CVE-2026-59796 1 Jetbrains 1 Teamcity 2026-07-14 N/A 8.1 HIGH
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
CVE-2026-59793 1 Jetbrains 1 Teamcity 2026-07-14 N/A 8.8 HIGH
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
CVE-2026-59795 1 Jetbrains 1 Teamcity 2026-07-13 N/A 8.1 HIGH
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
CVE-2026-59794 1 Jetbrains 1 Teamcity 2026-07-10 N/A 7.3 HIGH
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
CVE-2026-44413 1 Jetbrains 1 Teamcity 2026-06-17 N/A 8.2 HIGH
In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
CVE-2026-28196 1 Jetbrains 1 Teamcity 2026-06-17 N/A 2.3 LOW
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
CVE-2026-28195 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.3 MEDIUM
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations