CVE-2026-59796
JetBrains TeamCity Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-59796 is a missing authorization vulnerability in JetBrains TeamCity that allows authenticated low-privileged users to modify CI/CD pipelines beyond their intended permission scope. The flaw affects all TeamCity versions before 2026.1.2 and was disclosed on July 10, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, JetBrains).

Detalhes técnicos

The root cause is classified as CWE-862 (Missing Authorization), meaning the application fails to perform adequate authorization checks when a user attempts to access or modify pipeline resources. An authenticated attacker with low-level privileges can send crafted network requests to TeamCity's pipeline management endpoints, bypassing permission enforcement and altering build configurations or execution workflows they should not have access to. No user interaction is required, and the attack complexity is low, making it straightforward for any valid TeamCity account holder to exploit (GitHub Advisory).

Impacto

Successful exploitation allows a low-privileged authenticated user to modify CI/CD pipeline configurations and build workflows beyond their authorized scope, resulting in high confidentiality and integrity impacts with no availability impact. An attacker could tamper with build scripts, inject malicious steps into pipelines, or access sensitive build artifacts and environment variables, potentially enabling supply chain compromise or lateral movement within the development infrastructure (GitHub Advisory, JetBrains).

Etapas de exploração

  1. Reconnaissance: Identify a JetBrains TeamCity instance running a version prior to 2026.1.2, accessible over the network. Obtain or compromise a low-privileged TeamCity user account.
  2. Authentication: Log in to the TeamCity instance using the low-privileged credentials to obtain a valid session token or API key.
  3. Identify target pipeline: Browse or enumerate available build configurations and pipelines, including those the low-privileged account should not have write access to.
  4. Craft unauthorized modification request: Send an authenticated HTTP request (e.g., REST API call or web UI form submission) targeting a pipeline configuration endpoint for a project outside the user's permission scope, exploiting the missing authorization check.
  5. Modify pipeline: Alter build steps, inject malicious scripts, change artifact paths, or modify environment variables within the target pipeline configuration.
  6. Trigger build: Optionally trigger a build run to execute the modified pipeline, potentially exfiltrating secrets, deploying malicious artifacts, or establishing persistence within the build environment (GitHub Advisory).

Indicadores de compromisso

  • Logs: TeamCity audit logs showing pipeline or build configuration modification events attributed to low-privileged user accounts that do not normally have write access to those projects; unexpected REST API calls to pipeline configuration endpoints from non-admin users.
  • Network: Unusual authenticated HTTP requests (PUT/POST) to TeamCity REST API endpoints such as /app/rest/buildTypes/ or /app/rest/projects/ from accounts with limited roles.
  • Application: Unexpected changes to build step definitions, added or modified build scripts, altered environment variable values, or new artifact publishing rules in pipelines not owned by the modifying user.
  • Process: Build agents executing unexpected scripts or commands introduced via tampered pipeline configurations.

Mitigação e soluções alternativas

JetBrains has released TeamCity version 2026.1.2, which addresses this vulnerability; upgrading to this version or later is the recommended remediation (JetBrains). As an interim workaround, administrators should restrict TeamCity user access to trusted administrators only and audit recent pipeline modification history for unauthorized changes. Reviewing and tightening role-based access control assignments within TeamCity projects can further reduce exposure until patching is complete.

Reações da comunidade

The vulnerability was covered by several security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and VPNcentral as part of broader reporting on JetBrains patching six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA in July 2026 (GBHackers, CyberSecurityNews, VPNcentral). Community reaction was moderate, with attention focused on the pipeline tampering risk given TeamCity's role in CI/CD supply chains. No notable individual researcher commentary or vendor statements beyond the standard JetBrains security advisory page were identified.

Recursos adicionais


OrigemEste relatório foi gerado usando IA

Relacionado JetBrains TeamCity Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-63077CRITICAL9.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NãoSimJul 27, 2026
CVE-2026-59793HIGH8.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NãoSimJul 10, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NãoSimJul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NãoSimJul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NãoSimJul 10, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades