Executive brief
JetBrains TeamCity, a popular continuous integration and deployment server, is affected by a security vulnerability on its SAML login page. An attacker with high-level administrative privileges could inject malicious scripts that execute in the browsers of other users when they visit the login page. While the risk is rated as low, this could potentially be used to capture sensitive session information or perform unauthorized actions on behalf of other users.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in JetBrains TeamCity versions prior to 2026.1 within the SAML authentication component. The flaw is classified as CWE-79, resulting from improper neutralization of input during web page generation on the SAML login page. An attacker with high privileges (PR:H) can inject malicious scripts that are subsequently served to other users. Exploitation requires a victim to interact with the affected page (UI:R). The vulnerability has been addressed in TeamCity version 2026.1.
Affected products
- JetBrains TeamCity Before 2026.1
Timeline
- 2026-05-29: advisory: Initial disclosure by JetBrains and NVD publication.
- 2026-05-29: patched: Fixed in version 2026.1.