CVE-2026-28194
JetBrains TeamCity vulnerability analysis and mitigation

Overview

CVE-2026-28194 is an open redirect vulnerability (CWE-601) in JetBrains TeamCity affecting all versions before 2025.11.3, specifically within the React project creation flow. The vulnerability was disclosed on February 25, 2026, with JetBrains as the assigning CNA. CVSS v3.1 scores differ by source: NVD rates it 6.1 (Medium) while JetBrains' own assessment is 4.3 (Medium) (JetBrains Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect), rooted in insufficient validation of redirect URLs within TeamCity's React-based project creation workflow. An unauthenticated remote attacker can craft a malicious link that, when clicked by an authenticated TeamCity user navigating the project creation flow, causes the application to redirect the victim's browser to an attacker-controlled external site. Exploitation requires no privileges but does require user interaction (victim clicking a crafted link), and the changed scope in NVD's scoring reflects the cross-site nature of the redirect impact (JetBrains Advisory, Red Hat CVE).

Impact

Successful exploitation allows an attacker to redirect TeamCity users to arbitrary external websites, enabling phishing campaigns, credential harvesting, or malware distribution targeting TeamCity users. The confidentiality impact is limited (low-level information disclosure via redirect), with no direct impact on system integrity or availability. Because TeamCity is commonly used in CI/CD pipelines by developers and DevOps teams, successful phishing via this vector could lead to compromise of developer credentials with broader downstream consequences (JetBrains Advisory, Red Hat CVE).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is extremely low at 0.000030, reflecting minimal near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Nessus (plugin 300067) and Qualys (QID 530982) (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible JetBrains TeamCity instances running versions prior to 2025.11.3 using tools like Shodan or Censys, or target known TeamCity deployments within an organization.
  2. Craft malicious URL: Construct a TeamCity project creation flow URL that includes a redirect parameter pointing to an attacker-controlled domain (e.g., https://teamcity.target.com/createProject?redirectUrl=https://attacker.com/phishing).
  3. Deliver the link: Send the crafted URL to a TeamCity user via email, chat, or other social engineering channels, disguising it as a legitimate TeamCity project creation invitation.
  4. User interaction: When the victim clicks the link and interacts with the project creation flow, TeamCity processes the redirect parameter without adequate validation and redirects the user's browser to the attacker-controlled site.
  5. Achieve objective: The attacker's site presents a phishing page (e.g., a fake TeamCity login or corporate SSO page) to harvest credentials or deliver malware (JetBrains Advisory).

Indicators of compromise

  • Network: Outbound HTTP redirects (301/302 responses) from TeamCity server to external, non-organizational domains originating from project creation flow endpoints.
  • Logs: TeamCity access logs showing requests to project creation endpoints (e.g., /createProject) with suspicious or external redirectUrl or similar redirect parameters pointing to non-internal domains.
  • Logs: Web proxy or firewall logs showing users being redirected from TeamCity to unexpected external URLs shortly after accessing project creation pages.
  • User Reports: End-user reports of being unexpectedly redirected to unfamiliar login pages or external sites after clicking TeamCity project creation links.

Mitigation and workarounds

JetBrains has released a fix in TeamCity version 2025.11.3, which resolves the open redirect in the React project creation flow. Organizations should upgrade all TeamCity installations to version 2025.11.3 or later as the primary remediation. As an interim measure, administrators should educate users to verify URLs before clicking TeamCity links, monitor TeamCity logs for suspicious redirect activity, and consider restricting external network access from TeamCity servers where feasible (JetBrains Advisory).

Additional resources


SourceThis report was generated using AI

Related JetBrains TeamCity vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63077CRITICAL9.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
YesYesJul 27, 2026
CVE-2026-59793HIGH8.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management