Executive brief
JetBrains TeamCity, a platform used by software teams to automate building and testing code, contained a security flaw that allowed unauthorized users to modify build pipelines. An attacker with basic user access could change how software is built or deployed, potentially leading to the injection of malicious code into the company's software products. This issue has been resolved in version 2026.1.2.
Technical details
A missing authorization vulnerability (CWE-862) in JetBrains TeamCity allowed authenticated users with low-level privileges to modify build pipelines. The flaw stems from improper permission checks within the pipeline management component. An attacker with network access and valid credentials could exploit this to alter build configurations, potentially leading to unauthorized code execution or data exfiltration during the CI/CD process. The vulnerability is addressed in TeamCity version 2026.1.2.
Affected products
- JetBrains TeamCity before 2026.1.2
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory