CVE-2025-68267
JetBrains TeamCity vulnerability analysis and mitigation

Overview

CVE-2025-68267 is a least privilege violation vulnerability in JetBrains TeamCity that allows excessive privileges due to improper token storage. Specifically, the system stores GitHub personal access tokens instead of the more restrictive installation tokens, potentially granting attackers broader access than intended. All TeamCity versions before 2025.11.1 are affected. The vulnerability was published on December 16, 2025, and carries a CVSS v3.1 base score of 6.5 (Medium) (JetBrains Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-272 (Least Privilege Violation): TeamCity stores GitHub personal access tokens — which carry broad, user-level permissions — instead of GitHub App installation tokens, which are scoped and time-limited. This means that if the stored token is accessed or leaked, an attacker gains the full privileges associated with the personal access token rather than the narrower permissions of an installation token. The vulnerability is network-accessible, requires no authentication, and no user interaction, making it exploitable remotely without preconditions beyond network reachability to the TeamCity instance (JetBrains Advisory, Red Hat CVE).

Impact

Successful exploitation could allow an attacker to gain unauthorized access to confidential data and modify build configurations by leveraging the overprivileged GitHub personal access token stored by TeamCity. The confidentiality and integrity of connected GitHub repositories and CI/CD pipelines are at risk, as the token may grant read/write access to source code, secrets, and repository settings. Availability is not directly impacted, but compromise of CI/CD infrastructure could enable supply chain attacks or lateral movement into connected systems (Red Hat CVE, JetBrains Advisory).

Exploitability

As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat CVE). No threat actor attribution has been reported. The EPSS score is extremely low at approximately 0.002%, reflecting the current absence of active exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 279406) and Qualys (QID 530771) (Tenable, Qualys).

Mitigation and workarounds

JetBrains has released TeamCity version 2025.11.1, which addresses this vulnerability by correcting the token storage mechanism to use installation tokens instead of personal access tokens (JetBrains Advisory). Organizations should upgrade to version 2025.11.1 or later immediately. As additional remediation steps, administrators should review and rotate all GitHub personal access tokens associated with TeamCity integrations, audit connected GitHub App permissions, and monitor for any unauthorized changes to build configurations or repository access. Implementing network segmentation for CI/CD infrastructure is also recommended as a defense-in-depth measure.

Additional resources


SourceThis report was generated using AI

Related JetBrains TeamCity vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63077CRITICAL9.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
YesYesJul 27, 2026
CVE-2026-65906HIGH8.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 23, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management