VendorsJetBrainsteamcityall versions
Vulnerabilities

JetBrains TeamCity

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

275CVEs
CVE-2019-12157
In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
Published 2019-10-02 · Modified
10.0EPSS 0.018
CVE-2026-65906
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
Published 2026-07-23 · Analyzed
10.0EPSS 0.007
CVE-2023-42793
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
Published 2023-09-19 · Analyzed
9.8KEV1 PoCEPSS 1.000
CVE-2024-27198
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
Published 2024-03-04 · Analyzed
9.8KEV1 PoCEPSS 0.999
CVE-2024-23917
In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
Published 2024-02-06 · Modified
9.8EPSS 0.540
CVE-2019-15039
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.
Published 2019-10-01 · Modified
9.81 PoCEPSS 0.129
CVE-2026-63077
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Published 2026-07-27 · Analyzed
9.8KEVEPSS 0.098
CVE-2019-18364
In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
Published 2019-10-31 · Modified
9.8EPSS 0.035
CVE-2021-31915
In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.
Published 2021-05-11 · Modified
9.8EPSS 0.032
CVE-2021-31909
In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.
Published 2021-05-11 · Modified
9.8EPSS 0.032
CVE-2021-31914
In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.
Published 2021-05-11 · Modified
9.8EPSS 0.023
CVE-2022-25263
JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
Published 2022-02-25 · Modified
9.8EPSS 0.020
CVE-2021-43193
In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.
Published 2021-11-09 · Modified
9.8EPSS 0.020
CVE-2021-37544
In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.
Published 2021-08-06 · Modified
9.8EPSS 0.012
CVE-2022-24331
In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
Published 2022-02-25 · Modified
9.8EPSS 0.011
CVE-2021-43202
In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
Published 2021-11-30 · Modified
9.8EPSS 0.011
CVE-2021-43200
In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.
Published 2021-11-09 · Modified
9.8EPSS 0.011
CVE-2022-24340
In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
Published 2022-02-25 · Modified
9.8EPSS 0.010
CVE-2023-34218
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible
Published 2023-05-31 · Modified
9.8EPSS 0.006
CVE-2025-46433
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
Published 2025-04-25 · Analyzed
9.8EPSS 0.005
CVE-2024-36470
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
Published 2024-05-29 · Analyzed
9.8EPSS 0.005
CVE-2024-41827
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
Published 2024-07-22 · Modified
9.8EPSS 0.004
CVE-2022-48342
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
Published 2023-02-23 · Modified
9.8EPSS 0.003
CVE-2025-54530
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
Published 2025-07-28 · Analyzed
9.8EPSS 0.002
CVE-2025-54531
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
Published 2025-07-28 · Analyzed
9.4EPSS 0.003
CVE-2025-26492
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
Published 2025-02-11 · Analyzed
9.1EPSS 0.004
CVE-2019-15036
An issue was discovered in JetBrains TeamCity 2018.2.4. A TeamCity Project administrator could execute any command on the server machine. The issue was fixed in TeamCity 2018.2.5 and 2019.1.
Published 2019-10-02 · Modified
9.0EPSS 0.016
CVE-2022-24342
In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
Published 2022-02-25 · Modified
8.8EPSS 0.033
CVE-2021-31912
In JetBrains TeamCity before 2020.2.3, account takeover was potentially possible during a password reset.
Published 2021-05-11 · Modified
8.8EPSS 0.012
CVE-2020-15825
In JetBrains TeamCity before 2020.1, users with the Modify Group permission can elevate other users' privileges.
Published 2020-08-08 · Modified
8.8EPSS 0.011
CVE-2022-36322
In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
Published 2022-07-20 · Modified
8.8EPSS 0.006
CVE-2026-49373
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
Published 2026-05-29 · Analyzed
8.8EPSS 0.006
CVE-2026-59793
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
Published 2026-07-10 · Analyzed
8.8EPSS 0.005
CVE-2023-39173
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain full account access
Published 2023-07-25 · Modified
8.8EPSS 0.004
CVE-2023-50870
In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
Published 2023-12-15 · Modified
8.8EPSS 0.003
CVE-2024-56351
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
Published 2024-12-20 · Analyzed
8.8EPSS 0.003
CVE-2025-54528
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow
Published 2025-07-28 · Analyzed
8.8EPSS 0.002
CVE-2025-54536
In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
Published 2025-07-28 · Analyzed
8.8EPSS 0.002
CVE-2026-49371
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
Published 2026-05-29 · Analyzed
8.2EPSS 0.004
CVE-2026-44413
In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
Published 2026-05-11 · Analyzed
8.2EPSS 0.003
1 / 7Next →