
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59793 is an arbitrary file access vulnerability in JetBrains TeamCity affecting all versions before 2026.1.2. The flaw exists in the Perforce VCS (Version Control System) integration and allows authenticated low-privileged users to access arbitrary files on the TeamCity server over the network. It was published on July 10, 2026, with a patch available in TeamCity 2026.1.2. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, JetBrains).
The root cause is classified as CWE-73 (External Control of File Name or Path), where user-supplied input is used to influence file system paths without adequate validation or sanitization. An attacker with low-level authenticated access can manipulate path-related parameters within the Perforce VCS integration to traverse or reference arbitrary files on the server's file system. The attack is network-based, requires no user interaction, and has low attack complexity, making it straightforward to exploit once authenticated. No public proof-of-concept code has been identified at this time (GitHub Advisory, JetBrains).
Successful exploitation allows any authenticated low-privileged user to read arbitrary files on the TeamCity server, potentially exposing sensitive configuration files, credentials, build secrets, API tokens, and source code. The CVSS scoring also reflects high integrity and availability impacts, suggesting the vulnerability may enable file manipulation or disruption in addition to disclosure. Access to build server secrets could facilitate lateral movement into connected development infrastructure, supply chain compromise, or further privilege escalation (GitHub Advisory).
../../) as input to the Perforce VCS integration parameter to reference files outside the intended directory scope.../, %2e%2e%2f, or absolute paths outside expected repository directories.teamcity-server.log, database.properties, .env files, or SSH keys) by the TeamCity service account outside of normal build operations.JetBrains has released a patch in TeamCity version 2026.1.2, which resolves this vulnerability. Organizations should upgrade to version 2026.1.2 or later as the primary remediation step. If immediate patching is not feasible, a temporary workaround is to restrict or disable the Perforce VCS integration until the patch can be applied. Additionally, limiting TeamCity user permissions to the minimum necessary and monitoring VCS integration activity can reduce exposure (JetBrains, GitHub Advisory).
Coverage of CVE-2026-59793 appeared across several security news outlets shortly after disclosure, including GBHackers, CyberSecurityNews, and SecurityOnline, typically in the context of JetBrains patching multiple vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA in the same release cycle (GBHackers, CyberSecurityNews). Social media activity was limited, with brief mentions on Bluesky and Mastodon. Community reaction was moderate, with no significant controversy or researcher deep-dives identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."