CVE-2026-28195
JetBrains TeamCity vulnerability analysis and mitigation

Overview

CVE-2026-28195 is a missing authorization vulnerability in JetBrains TeamCity that allows authenticated project developers to add parameters to build configurations without proper authorization checks. It affects all TeamCity versions before 2025.11.3 and was disclosed on February 25, 2026, with the CVE assigned by JetBrains s.r.o. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium), assigned by JetBrains (JetBrains Advisory).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the application fails to perform adequate authorization checks before allowing project developers to modify build configuration parameters. An authenticated attacker with project developer-level privileges can exploit this over the network (attack vector: Network, privileges required: Low) without any user interaction. No technical write-ups or public proof-of-concept code have been identified at this time (JetBrains Advisory).

Impact

Exploitation allows authenticated project developers to inject unauthorized parameters into build configurations, potentially altering build behavior, introducing malicious build steps, or manipulating build artifacts within the CI/CD pipeline. While there is no direct confidentiality or availability impact, the integrity impact could enable privilege escalation within the pipeline or facilitate supply chain compromise if malicious parameters influence downstream build outputs. The scope is limited to the affected TeamCity instance and does not directly affect external systems.

Exploitability

There is no evidence of public proof-of-concept code or active in-the-wild exploitation of this vulnerability. The EPSS score is extremely low at 0.00001, reflecting minimal current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access with at least project developer privileges, significantly limiting the attacker pool.

Exploitation steps

  1. Reconnaissance: Identify a JetBrains TeamCity instance running a version prior to 2025.11.3, accessible over the network.
  2. Authentication: Log in to the TeamCity instance using valid project developer credentials (low-privilege account).
  3. Navigate to build configuration: Access a project's build configuration settings panel where the developer has at least read access.
  4. Inject unauthorized parameters: Exploit the missing authorization check to add or modify build configuration parameters that the developer role should not be permitted to change — for example, injecting environment variables, build step commands, or artifact paths.
  5. Trigger a build: Initiate a build run so the injected parameters are executed within the CI/CD pipeline, potentially altering build output or executing unintended commands.

Indicators of compromise

  • Logs: TeamCity audit logs showing build configuration parameter additions or modifications by accounts with project developer roles that would not normally have such permissions; review teamcity-server.log and the audit trail in the TeamCity UI under Administration > Audit.
  • Build Configuration Changes: Unexpected or unauthorized parameters appearing in build configurations, particularly environment variables or custom script parameters added by developer-level accounts.
  • Build History: Unusual build runs triggered shortly after configuration changes by developer accounts, especially those producing unexpected artifacts or exhibiting anomalous behavior.

Mitigation and workarounds

JetBrains has released TeamCity version 2025.11.3, which addresses this authorization vulnerability; organizations should upgrade immediately (JetBrains Advisory). As interim mitigations, restrict project developer role permissions to the minimum necessary and audit recent build configuration changes for unauthorized parameter additions. Additionally, review and strengthen access control policies for build configuration modifications and monitor build configuration changes for suspicious activity.

Additional resources


SourceThis report was generated using AI

Related JetBrains TeamCity vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65906CRITICAL10
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 23, 2026
CVE-2026-63077CRITICAL9.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
YesYesJul 27, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management