
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28194 is an open redirect vulnerability (CWE-601) in JetBrains TeamCity affecting all versions before 2025.11.3, specifically within the React project creation flow. The vulnerability was disclosed on February 25, 2026, with JetBrains as the assigning CNA. CVSS v3.1 scores differ by source: NVD rates it 6.1 (Medium) while JetBrains' own assessment is 4.3 (Medium) (JetBrains Advisory, Red Hat CVE).
The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect), rooted in insufficient validation of redirect URLs within TeamCity's React-based project creation workflow. An unauthenticated remote attacker can craft a malicious link that, when clicked by an authenticated TeamCity user navigating the project creation flow, causes the application to redirect the victim's browser to an attacker-controlled external site. Exploitation requires no privileges but does require user interaction (victim clicking a crafted link), and the changed scope in NVD's scoring reflects the cross-site nature of the redirect impact (JetBrains Advisory, Red Hat CVE).
Successful exploitation allows an attacker to redirect TeamCity users to arbitrary external websites, enabling phishing campaigns, credential harvesting, or malware distribution targeting TeamCity users. The confidentiality impact is limited (low-level information disclosure via redirect), with no direct impact on system integrity or availability. Because TeamCity is commonly used in CI/CD pipelines by developers and DevOps teams, successful phishing via this vector could lead to compromise of developer credentials with broader downstream consequences (JetBrains Advisory, Red Hat CVE).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is extremely low at 0.000030, reflecting minimal near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Nessus (plugin 300067) and Qualys (QID 530982) (Red Hat CVE).
https://teamcity.target.com/createProject?redirectUrl=https://attacker.com/phishing)./createProject) with suspicious or external redirectUrl or similar redirect parameters pointing to non-internal domains.JetBrains has released a fix in TeamCity version 2025.11.3, which resolves the open redirect in the React project creation flow. Organizations should upgrade all TeamCity installations to version 2025.11.3 or later as the primary remediation. As an interim measure, administrators should educate users to verify URLs before clicking TeamCity links, monitor TeamCity logs for suspicious redirect activity, and consider restricting external network access from TeamCity servers where feasible (JetBrains Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."