Junglewise Threat Intelligence

CVE-2026-59794: JetBrains TeamCity stored XSS in cloud profile page

CVE-2026-59794 · Severity: high · CVSS 7.3 · Published 2026-07-10

Technologies: Jetbrains TeamCity. Vendors: Jetbrains.

Executive brief

JetBrains TeamCity, a popular platform for automating software builds and deployments, was found to have a security flaw in its cloud profile management page. An attacker could inject malicious scripts into the system that would then execute in the browsers of other users, such as administrators. This could lead to unauthorized access to sensitive build data or the hijacking of administrative sessions.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in JetBrains TeamCity before version 2026.1.2. The flaw is located in the cloud profile page, where the application fails to properly neutralize input provided by build agents. An attacker with low-privileged access to a build agent can report malicious data that is subsequently rendered in the web interface for other users. Successful exploitation requires a victim (typically an administrator) to view the affected cloud profile page, allowing the attacker to execute arbitrary JavaScript in the context of the victim's session. This can result in high impacts to confidentiality and integrity. The issue is resolved in TeamCity version 2026.1.2.

Affected products

  • JetBrains TeamCity before 2026.1.2

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References

Related threats