Junglewise Threat Intelligence

CVE-2026-44413: JetBrains TeamCity authentication bypass in server API

CVE-2026-44413 · Severity: high · CVSS 8.2 · Published 2026-05-11

Technologies: Jetbrains TeamCity. Vendors: Jetbrains.

Executive brief

JetBrains TeamCity, a platform used by software development teams to automate building and testing code, contains a security flaw that could allow unauthorized access to its internal programming interface (API). While the initial setup of the vulnerability requires an authenticated user, the resulting exposure could allow outsiders to access sensitive server data or perform unauthorized actions. This could lead to the theft of proprietary source code or disruption of the software delivery pipeline.

Technical details

A missing authentication vulnerability (CWE-306) exists in JetBrains TeamCity versions prior to 2026.1 and 2025.11.5. The flaw allows an authenticated user to perform actions that expose the server's API to unauthenticated remote actors. According to the vendor's CVSS metrics, the vulnerability is network-exploitable with low complexity and requires no user interaction once the exposure is triggered. Successful exploitation primarily impacts confidentiality, allowing an attacker to retrieve sensitive information from the server API. Users are advised to upgrade to version 2026.1 or 2025.11.5 to mitigate this risk.

Affected products

  • JetBrains TeamCity before 2026.1, 2025.11.5

Timeline

  • 2026-05-11: advisory: Initial advisory publication by JetBrains and NVD

References

Related threats