VendorsJetBrainsteamcityany version
Vulnerabilities

JetBrains TeamCity any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

265CVEs
CVE-2026-49377
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
Published 2026-05-29 · Analyzed
4.3EPSS 0.009
CVE-2020-7908
In JetBrains TeamCity before 2019.1.5, reverse tabnabbing was possible on several pages.
Published 2020-01-30 · Modified
4.3EPSS 0.008
CVE-2019-18365
In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.
Published 2019-10-31 · Modified
4.3EPSS 0.008
CVE-2019-12846
A user without the required permissions could gain access to some JetBrains TeamCity settings. The issue was fixed in TeamCity 2018.2.2.
Published 2019-07-03 · Modified
4.3EPSS 0.008
CVE-2020-27628
In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.
Published 2020-11-16 · Modified
4.3EPSS 0.007
CVE-2021-25774
In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
Published 2021-02-03 · Modified
4.3EPSS 0.007
CVE-2020-15826
In JetBrains TeamCity before 2020.1, users are able to assign more permissions than they have.
Published 2020-08-08 · Modified
4.3EPSS 0.006
CVE-2024-28173
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
Published 2024-03-06 · Analyzed
4.3EPSS 0.005
CVE-2025-52878
In JetBrains TeamCity before 2025.03.3 usernames were exposed to the users without proper permissions
Published 2025-06-23 · Analyzed
4.3EPSS 0.004
CVE-2023-34219
In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API
Published 2023-05-31 · Modified
4.3EPSS 0.004
CVE-2026-49378
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
Published 2026-05-29 · Analyzed
4.3EPSS 0.003
CVE-2024-56348
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of unauthorized agents
Published 2024-12-20 · Analyzed
4.3EPSS 0.003
CVE-2024-56350
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
Published 2024-12-20 · Analyzed
4.3EPSS 0.003
CVE-2025-24460
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
Published 2025-01-21 · Analyzed
4.3EPSS 0.003
CVE-2026-28195
In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations
Published 2026-02-25 · Analyzed
4.3EPSS 0.003
CVE-2025-54532
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies
Published 2025-07-28 · Analyzed
4.3EPSS 0.002
CVE-2025-54533
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
Published 2025-07-28 · Analyzed
4.3EPSS 0.002
CVE-2025-59455
In JetBrains TeamCity before 2025.07.2 project isolation bypass was possible due to race condition
Published 2025-09-17 · Analyzed
4.2EPSS 0.004
CVE-2020-11686
In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.
Published 2020-04-22 · Modified
4.0EPSS 0.007
CVE-2021-31906
In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.
Published 2021-05-11 · Modified
4.0EPSS 0.006
CVE-2021-26309
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.
Published 2021-05-11 · Modified
3.3EPSS 0.002
CVE-2025-67739
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
Published 2025-12-11 · Analyzed
3.1EPSS 0.002
CVE-2025-68164
In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test
Published 2025-12-16 · Analyzed
2.7EPSS 0.002
CVE-2025-68162
In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration
Published 2025-12-16 · Analyzed
2.7EPSS 0.002
CVE-2026-28196
In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk
Published 2026-02-25 · Analyzed
2.3EPSS 0.002
← Prev7 / 7