Executive brief
JetBrains TeamCity, a popular platform for automating software builds and deployments, contained a vulnerability in its SAML authentication plugin. This flaw allows attackers to redirect users from the legitimate TeamCity login page to a malicious website. Such redirects are typically used in phishing campaigns to trick employees into providing their credentials or downloading malware.
Technical details
An open redirect vulnerability (CWE-601) exists in the SAML plugin of JetBrains TeamCity prior to version 2026.1. The flaw is caused by insufficient validation of redirection parameters during the SAML authentication flow. A remote, unauthenticated attacker can exploit this by tricking a user into clicking a specially crafted URL. While the vulnerability does not allow direct data theft, it is a common primitive for phishing attacks or bypassing security controls that rely on domain trust. The issue is resolved in TeamCity version 2026.1.
Affected products
- JetBrains TeamCity before 2026.1
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory