
PEACH
Un cadre d’isolation des locataires
CVE-2026-59793 is an arbitrary file access vulnerability in JetBrains TeamCity affecting all versions before 2026.1.2. The flaw exists in the Perforce VCS (Version Control System) integration and allows authenticated low-privileged users to access arbitrary files on the TeamCity server over the network. It was published on July 10, 2026, with a patch released in TeamCity 2026.1.2. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, JetBrains).
The root cause is classified as CWE-73 (External Control of File Name or Path), where user-supplied input is used to influence file system paths without adequate sanitization or restriction. An authenticated attacker with low privileges can craft requests through the Perforce VCS integration to reference arbitrary file paths on the server, bypassing intended access controls. The attack is network-based, requires no user interaction, and has low complexity, making it straightforward to exploit once authenticated. Associated attack patterns include path manipulation techniques such as URL encoding, slash abuse, and alternate encoding to bypass validation logic (CAPEC-64, CAPEC-76, CAPEC-80) (GitHub Advisory).
Successful exploitation allows an authenticated low-privileged attacker to read arbitrary files on the TeamCity server, potentially exposing sensitive configuration files, credentials, build secrets, source code, and internal tokens. The CVSS scoring reflects high impacts across confidentiality, integrity, and availability, indicating that beyond file disclosure, the vulnerability could facilitate further compromise of the CI/CD pipeline and connected systems. Access to build secrets or VCS credentials could enable lateral movement into source code repositories or downstream infrastructure (GitHub Advisory, JetBrains).
/etc/passwd, TeamCity configuration files, or credential stores).../, %2e%2e%2f, %252e%252e) in parameters.database.properties, internal/ directory contents, or OS-level files like /etc/passwd) reflected in file access audit logs.JetBrains has released a fix in TeamCity version 2026.1.2; upgrading to this version or later is the primary recommended remediation (JetBrains, GitHub Advisory). As a temporary workaround if immediate patching is not feasible, administrators should restrict or disable the Perforce VCS integration until the patch can be applied. Additionally, limiting TeamCity access to trusted networks and enforcing the principle of least privilege for user accounts can reduce the attack surface.
Coverage of CVE-2026-59793 appeared across multiple security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and VPNcentral, typically in the context of a broader JetBrains patch release addressing six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA. Social media mentions were noted on Bluesky and Mastodon, with community discussion framing the issue as part of JetBrains' routine security advisory cycle. No notable independent researcher commentary or vendor statements beyond the official advisory were identified.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."