CVE-2026-59796
JetBrains TeamCity Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-59796 is a missing authorization vulnerability in JetBrains TeamCity that allows authenticated low-privileged users to modify CI/CD pipelines beyond their intended permission scope. The flaw affects all TeamCity versions before 2026.1.2 and was disclosed on July 10, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, JetBrains).

Détails techniques

The root cause is classified as CWE-862 (Missing Authorization), meaning the application fails to perform adequate authorization checks when a user attempts to access or modify pipeline resources. An authenticated attacker with low-level privileges can send crafted network requests to TeamCity's pipeline management endpoints, bypassing permission enforcement and altering build configurations or execution workflows they should not have access to. No user interaction is required, and the attack complexity is low, making it straightforward for any valid TeamCity account holder to exploit (GitHub Advisory).

Impact

Successful exploitation allows a low-privileged authenticated user to modify CI/CD pipeline configurations and build workflows beyond their authorized scope, resulting in high confidentiality and integrity impacts with no availability impact. An attacker could tamper with build scripts, inject malicious steps into pipelines, or access sensitive build artifacts and environment variables, potentially enabling supply chain compromise or lateral movement within the development infrastructure (GitHub Advisory, JetBrains).

Étapes d’exploitation

  1. Reconnaissance: Identify a JetBrains TeamCity instance running a version prior to 2026.1.2, accessible over the network. Obtain or compromise a low-privileged TeamCity user account.
  2. Authentication: Log in to the TeamCity instance using the low-privileged credentials to obtain a valid session token or API key.
  3. Identify target pipeline: Browse or enumerate available build configurations and pipelines, including those the low-privileged account should not have write access to.
  4. Craft unauthorized modification request: Send an authenticated HTTP request (e.g., REST API call or web UI form submission) targeting a pipeline configuration endpoint for a project outside the user's permission scope, exploiting the missing authorization check.
  5. Modify pipeline: Alter build steps, inject malicious scripts, change artifact paths, or modify environment variables within the target pipeline configuration.
  6. Trigger build: Optionally trigger a build run to execute the modified pipeline, potentially exfiltrating secrets, deploying malicious artifacts, or establishing persistence within the build environment (GitHub Advisory).

Indicateurs de compromis

  • Logs: TeamCity audit logs showing pipeline or build configuration modification events attributed to low-privileged user accounts that do not normally have write access to those projects; unexpected REST API calls to pipeline configuration endpoints from non-admin users.
  • Network: Unusual authenticated HTTP requests (PUT/POST) to TeamCity REST API endpoints such as /app/rest/buildTypes/ or /app/rest/projects/ from accounts with limited roles.
  • Application: Unexpected changes to build step definitions, added or modified build scripts, altered environment variable values, or new artifact publishing rules in pipelines not owned by the modifying user.
  • Process: Build agents executing unexpected scripts or commands introduced via tampered pipeline configurations.

Atténuation et solutions de contournement

JetBrains has released TeamCity version 2026.1.2, which addresses this vulnerability; upgrading to this version or later is the recommended remediation (JetBrains). As an interim workaround, administrators should restrict TeamCity user access to trusted administrators only and audit recent pipeline modification history for unauthorized changes. Reviewing and tightening role-based access control assignments within TeamCity projects can further reduce exposure until patching is complete.

Réactions de la communauté

The vulnerability was covered by several security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and VPNcentral as part of broader reporting on JetBrains patching six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA in July 2026 (GBHackers, CyberSecurityNews, VPNcentral). Community reaction was moderate, with attention focused on the pipeline tampering risk given TeamCity's role in CI/CD supply chains. No notable individual researcher commentary or vendor statements beyond the standard JetBrains security advisory page were identified.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté JetBrains TeamCity Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-63077CRITICAL9.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NonOuiJul 27, 2026
CVE-2026-59793HIGH8.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NonOuiJul 10, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NonOuiJul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NonOuiJul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NonOuiJul 10, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités