CVE-2026-59796
JetBrains TeamCity 취약성 분석 및 완화

개요

CVE-2026-59796 is a missing authorization vulnerability in JetBrains TeamCity that allows authenticated low-privileged users to modify CI/CD pipelines beyond their intended permission scope. The flaw affects all TeamCity versions before 2026.1.2 and was disclosed on July 10, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, JetBrains).

기술적 세부 사항

The root cause is classified as CWE-862 (Missing Authorization), meaning the application fails to perform adequate authorization checks when a user attempts to access or modify pipeline resources. An authenticated attacker with low-level privileges can send crafted network requests to TeamCity's pipeline management endpoints, bypassing permission enforcement and altering build configurations or execution workflows they should not have access to. No user interaction is required, and the attack complexity is low, making it straightforward for any valid TeamCity account holder to exploit (GitHub Advisory).

영향

Successful exploitation allows a low-privileged authenticated user to modify CI/CD pipeline configurations and build workflows beyond their authorized scope, resulting in high confidentiality and integrity impacts with no availability impact. An attacker could tamper with build scripts, inject malicious steps into pipelines, or access sensitive build artifacts and environment variables, potentially enabling supply chain compromise or lateral movement within the development infrastructure (GitHub Advisory, JetBrains).

착취 단계

  1. Reconnaissance: Identify a JetBrains TeamCity instance running a version prior to 2026.1.2, accessible over the network. Obtain or compromise a low-privileged TeamCity user account.
  2. Authentication: Log in to the TeamCity instance using the low-privileged credentials to obtain a valid session token or API key.
  3. Identify target pipeline: Browse or enumerate available build configurations and pipelines, including those the low-privileged account should not have write access to.
  4. Craft unauthorized modification request: Send an authenticated HTTP request (e.g., REST API call or web UI form submission) targeting a pipeline configuration endpoint for a project outside the user's permission scope, exploiting the missing authorization check.
  5. Modify pipeline: Alter build steps, inject malicious scripts, change artifact paths, or modify environment variables within the target pipeline configuration.
  6. Trigger build: Optionally trigger a build run to execute the modified pipeline, potentially exfiltrating secrets, deploying malicious artifacts, or establishing persistence within the build environment (GitHub Advisory).

타협의 징후

  • Logs: TeamCity audit logs showing pipeline or build configuration modification events attributed to low-privileged user accounts that do not normally have write access to those projects; unexpected REST API calls to pipeline configuration endpoints from non-admin users.
  • Network: Unusual authenticated HTTP requests (PUT/POST) to TeamCity REST API endpoints such as /app/rest/buildTypes/ or /app/rest/projects/ from accounts with limited roles.
  • Application: Unexpected changes to build step definitions, added or modified build scripts, altered environment variable values, or new artifact publishing rules in pipelines not owned by the modifying user.
  • Process: Build agents executing unexpected scripts or commands introduced via tampered pipeline configurations.

완화 및 해결 방법

JetBrains has released TeamCity version 2026.1.2, which addresses this vulnerability; upgrading to this version or later is the recommended remediation (JetBrains). As an interim workaround, administrators should restrict TeamCity user access to trusted administrators only and audit recent pipeline modification history for unauthorized changes. Reviewing and tightening role-based access control assignments within TeamCity projects can further reduce exposure until patching is complete.

커뮤니티 반응

The vulnerability was covered by several security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and VPNcentral as part of broader reporting on JetBrains patching six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA in July 2026 (GBHackers, CyberSecurityNews, VPNcentral). Community reaction was moderate, with attention focused on the pipeline tampering risk given TeamCity's role in CI/CD supply chains. No notable individual researcher commentary or vendor statements beyond the standard JetBrains security advisory page were identified.

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 JetBrains TeamCity 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-63077CRITICAL9.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
아니요Jul 27, 2026
CVE-2026-59793HIGH8.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
아니요Jul 10, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
아니요Jul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
아니요Jul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
아니요Jul 10, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자