CVE-2026-59796
JetBrains TeamCity Schwachstellenanalyse und -minderung

Überblick

CVE-2026-59796 is a missing authorization vulnerability in JetBrains TeamCity that allows authenticated low-privileged users to modify CI/CD pipelines beyond their intended permission scope. The flaw affects all TeamCity versions before 2026.1.2 and was disclosed on July 10, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, JetBrains).

Technische Details

The root cause is classified as CWE-862 (Missing Authorization), meaning the application fails to perform adequate authorization checks when a user attempts to access or modify pipeline resources. An authenticated attacker with low-level privileges can send crafted network requests to TeamCity's pipeline management endpoints, bypassing permission enforcement and altering build configurations or execution workflows they should not have access to. No user interaction is required, and the attack complexity is low, making it straightforward for any valid TeamCity account holder to exploit (GitHub Advisory).

Aufprall

Successful exploitation allows a low-privileged authenticated user to modify CI/CD pipeline configurations and build workflows beyond their authorized scope, resulting in high confidentiality and integrity impacts with no availability impact. An attacker could tamper with build scripts, inject malicious steps into pipelines, or access sensitive build artifacts and environment variables, potentially enabling supply chain compromise or lateral movement within the development infrastructure (GitHub Advisory, JetBrains).

Ausnutzungsschritte

  1. Reconnaissance: Identify a JetBrains TeamCity instance running a version prior to 2026.1.2, accessible over the network. Obtain or compromise a low-privileged TeamCity user account.
  2. Authentication: Log in to the TeamCity instance using the low-privileged credentials to obtain a valid session token or API key.
  3. Identify target pipeline: Browse or enumerate available build configurations and pipelines, including those the low-privileged account should not have write access to.
  4. Craft unauthorized modification request: Send an authenticated HTTP request (e.g., REST API call or web UI form submission) targeting a pipeline configuration endpoint for a project outside the user's permission scope, exploiting the missing authorization check.
  5. Modify pipeline: Alter build steps, inject malicious scripts, change artifact paths, or modify environment variables within the target pipeline configuration.
  6. Trigger build: Optionally trigger a build run to execute the modified pipeline, potentially exfiltrating secrets, deploying malicious artifacts, or establishing persistence within the build environment (GitHub Advisory).

Indikatoren für Kompromittierung

  • Logs: TeamCity audit logs showing pipeline or build configuration modification events attributed to low-privileged user accounts that do not normally have write access to those projects; unexpected REST API calls to pipeline configuration endpoints from non-admin users.
  • Network: Unusual authenticated HTTP requests (PUT/POST) to TeamCity REST API endpoints such as /app/rest/buildTypes/ or /app/rest/projects/ from accounts with limited roles.
  • Application: Unexpected changes to build step definitions, added or modified build scripts, altered environment variable values, or new artifact publishing rules in pipelines not owned by the modifying user.
  • Process: Build agents executing unexpected scripts or commands introduced via tampered pipeline configurations.

Risikominderung und Problemumgehungen

JetBrains has released TeamCity version 2026.1.2, which addresses this vulnerability; upgrading to this version or later is the recommended remediation (JetBrains). As an interim workaround, administrators should restrict TeamCity user access to trusted administrators only and audit recent pipeline modification history for unauthorized changes. Reviewing and tightening role-based access control assignments within TeamCity projects can further reduce exposure until patching is complete.

Reaktionen der Community

The vulnerability was covered by several security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and VPNcentral as part of broader reporting on JetBrains patching six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA in July 2026 (GBHackers, CyberSecurityNews, VPNcentral). Community reaction was moderate, with attention focused on the pipeline tampering risk given TeamCity's role in CI/CD supply chains. No notable individual researcher commentary or vendor statements beyond the standard JetBrains security advisory page were identified.

Zusätzliche Ressourcen


QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt JetBrains TeamCity Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-63077CRITICAL9.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NeinJaJul 27, 2026
CVE-2026-59793HIGH8.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NeinJaJul 10, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NeinJaJul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NeinJaJul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NeinJaJul 10, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement