
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68267 is a least privilege violation vulnerability in JetBrains TeamCity that allows excessive privileges due to improper token storage. Specifically, the system stores GitHub personal access tokens instead of the more restrictive installation tokens, potentially granting attackers broader access than intended. All TeamCity versions before 2025.11.1 are affected. The vulnerability was published on December 16, 2025, and carries a CVSS v3.1 base score of 6.5 (Medium) (JetBrains Advisory, Red Hat CVE).
The root cause is classified as CWE-272 (Least Privilege Violation): TeamCity stores GitHub personal access tokens — which carry broad, user-level permissions — instead of GitHub App installation tokens, which are scoped and time-limited. This means that if the stored token is accessed or leaked, an attacker gains the full privileges associated with the personal access token rather than the narrower permissions of an installation token. The vulnerability is network-accessible, requires no authentication, and no user interaction, making it exploitable remotely without preconditions beyond network reachability to the TeamCity instance (JetBrains Advisory, Red Hat CVE).
Successful exploitation could allow an attacker to gain unauthorized access to confidential data and modify build configurations by leveraging the overprivileged GitHub personal access token stored by TeamCity. The confidentiality and integrity of connected GitHub repositories and CI/CD pipelines are at risk, as the token may grant read/write access to source code, secrets, and repository settings. Availability is not directly impacted, but compromise of CI/CD infrastructure could enable supply chain attacks or lateral movement into connected systems (Red Hat CVE, JetBrains Advisory).
As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat CVE). No threat actor attribution has been reported. The EPSS score is extremely low at approximately 0.002%, reflecting the current absence of active exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 279406) and Qualys (QID 530771) (Tenable, Qualys).
JetBrains has released TeamCity version 2025.11.1, which addresses this vulnerability by correcting the token storage mechanism to use installation tokens instead of personal access tokens (JetBrains Advisory). Organizations should upgrade to version 2025.11.1 or later immediately. As additional remediation steps, administrators should review and rotate all GitHub personal access tokens associated with TeamCity integrations, audit connected GitHub App permissions, and monitor for any unauthorized changes to build configurations or repository access. Implementing network segmentation for CI/CD infrastructure is also recommended as a defense-in-depth measure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."