Executive brief
JetBrains TeamCity, a platform used by software teams to automate building and testing code, contains a security flaw in its SAML authentication plugin. This vulnerability allows for insufficient validation of usernames during the login process. If exploited, it could potentially allow unauthorized individuals to gain limited access to the system or manipulate user identity data, impacting the integrity of the development environment.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the JetBrains TeamCity SAML plugin for versions prior to 2026.1. The root cause is insufficient validation of usernames provided during the SAML authentication flow. A remote, unauthenticated attacker can exploit this over the network without user interaction. Successful exploitation could lead to unauthorized access or data modification (Low impact to Confidentiality and Integrity). The issue is addressed in TeamCity version 2026.1.
Affected products
- JetBrains TeamCity before 2026.1
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory