Junglewise Threat Intelligence

CVE-2026-49373: JetBrains TeamCity remote code execution in Perforce connection settings

CVE-2026-49373 · Severity: high · CVSS 7.1 · Published 2026-05-29

Technologies: Jetbrains TeamCity. Vendors: Jetbrains.

Executive brief

JetBrains TeamCity, a popular continuous integration and deployment server, is vulnerable to a security flaw in its Perforce integration. An attacker with basic user permissions could exploit this to run unauthorized commands on the server. This could lead to the theft of sensitive source code, intellectual property, or full compromise of the build environment.

Technical details

A remote code execution vulnerability exists in JetBrains TeamCity before version 2026.1 due to improper neutralization of argument delimiters (CWE-88) within Perforce connection settings. An authenticated attacker with low-level privileges (PR:L) can inject malicious arguments into the Perforce command-line interface via the web UI or API. This allows for the execution of arbitrary commands on the TeamCity server host. The vulnerability is reachable over the network and does not require user interaction. JetBrains has addressed this issue in the 2026.1 release.

Affected products

  • JetBrains TeamCity before 2026.1

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory

References

Related threats