Executive brief
JetBrains TeamCity, a popular continuous integration and deployment server, contained a vulnerability in its Perforce version control integration. This flaw allowed an attacker with low-level access to read or access sensitive files on the server. Such access could lead to the theft of source code, configuration secrets, or other critical intellectual property, potentially compromising the entire software delivery pipeline.
Technical details
A path traversal or external control of file name/path vulnerability (CWE-73) exists in the Perforce VCS integration of JetBrains TeamCity. An authenticated attacker with low privileges can exploit this flaw via the network to access arbitrary files on the host system. The root cause involves insufficient validation of file paths provided through the Perforce integration. Successful exploitation could result in full loss of confidentiality, integrity, and availability of the server. The issue is resolved in TeamCity version 2026.1.2.
Affected products
- JetBrains TeamCity before 2026.1.2
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory