Executive brief
JetBrains TeamCity, a platform used by software teams to automate building and testing code, was found to leak sensitive credentials in system thread names. An authenticated user could potentially view these thread names through monitoring tools or logs, leading to the exposure of passwords or access tokens. This could allow an attacker to gain unauthorized access to other integrated systems or sensitive project data.
Technical details
A vulnerability in JetBrains TeamCity (classified as CWE-522: Insufficiently Protected Credentials) allowed sensitive credentials to be exposed within the names of execution threads. This issue affects versions prior to 2026.1. An attacker with low-privileged network access could potentially observe these credentials by inspecting thread dumps, system logs, or monitoring interfaces where thread names are visible. The vulnerability has a CVSS score of 6.5, reflecting high confidentiality impact but requiring at least basic user authentication. JetBrains has addressed this issue in version 2026.1.
Affected products
- JetBrains TeamCity before 2026.1
Timeline
- 2026-05-29: advisory: CVE-2026-49379 published by JetBrains
- 2026-05-29: patched: Fixed in version 2026.1