Junglewise Threat Intelligence

CVE-2026-49374: JetBrains TeamCity improper permission checks in build configuration

CVE-2026-49374 · Severity: high · CVSS 7.6 · Published 2026-05-29

Technologies: Jetbrains TeamCity. Vendors: Jetbrains.

Executive brief

JetBrains TeamCity, a platform used by software teams to automate the building and testing of code, contained a security flaw that allowed unauthorized users to view sensitive build configuration parameters. These parameters often contain internal environment details or secrets required for the software development process. An attacker with low-level access to the system could exploit this to gain information that should be restricted, potentially compromising the integrity of the software delivery pipeline.

Technical details

A missing authorization vulnerability (CWE-862) exists in JetBrains TeamCity versions prior to 2026.1. The flaw is rooted in improper permission checks within the build configuration component, which fails to correctly restrict access to configuration parameters. A remote attacker with basic authenticated access (low privileges) can exploit this over the network without any user interaction. Successful exploitation allows the attacker to read sensitive build parameters, which may lead to further information disclosure or unauthorized modifications to the build environment. The issue is resolved in TeamCity version 2026.1.

Affected products

  • JetBrains TeamCity before 2026.1

Timeline

  • 2026-05-29: advisory: CVE-2026-49374 published by JetBrains
  • 2026-05-29: patched: Fixed in version 2026.1

References

Related threats