Junglewise Threat Intelligence

CVE-2026-49378: JetBrains TeamCity credential exposure via parameter autocompletion

CVE-2026-49378 · Severity: medium · CVSS 4.3 · Published 2026-05-29

Technologies: Jetbrains TeamCity. Vendors: Jetbrains.

Executive brief

JetBrains TeamCity, a platform used by software teams to automate building and testing code, contained a flaw where sensitive credential information was inadvertently visible. Specifically, these credentials could be exposed to authorized users through the user interface's autocompletion feature. This could allow internal users with basic access to view sensitive keys or passwords they are not supposed to see, potentially leading to unauthorized access to other connected systems.

Technical details

A missing authorization vulnerability (CWE-862) in JetBrains TeamCity before version 2026.1 allowed the exposure of sensitive credential parameters. The flaw exists in the parameter autocompletion component of the web interface. A remote attacker with low-privileged authenticated access could trigger autocompletion suggestions to reveal sensitive credential strings that should otherwise be masked or restricted. This is categorized with a CVSS score of 4.3, reflecting a partial loss of confidentiality. The issue is resolved in TeamCity version 2026.1.

Affected products

  • JetBrains TeamCity before 2026.1

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory

References

Related threats