CVE-2026-59796
JetBrains TeamCity vulnerability analysis and mitigation

Overview

CVE-2026-59796 is a missing authorization vulnerability in JetBrains TeamCity that allows authenticated low-privileged users to modify CI/CD pipelines beyond their intended permission scope. It affects all versions of JetBrains TeamCity before 2026.1.2 and was published on July 10, 2026. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, JetBrains).

Technical details

The root cause is classified as CWE-862 (Missing Authorization): the application fails to perform adequate authorization checks when a user attempts to modify pipeline configurations, allowing privilege escalation within the platform's permission model. An attacker with a valid low-privileged TeamCity account can send crafted network requests to pipeline management endpoints, bypassing the expected permission boundaries to alter build configurations and execution workflows. No user interaction is required, and the attack complexity is low, making exploitation straightforward for any authenticated user (GitHub Advisory, JetBrains).

Impact

Successful exploitation allows a low-privileged authenticated attacker to tamper with CI/CD pipeline configurations and build workflows they are not authorized to access, resulting in high integrity and high confidentiality impact with no availability impact. An attacker could inject malicious build steps, exfiltrate secrets embedded in pipelines (e.g., API keys, credentials), redirect build artifacts, or sabotage software delivery processes. This could facilitate supply chain attacks or lateral movement within an organization's development infrastructure (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible JetBrains TeamCity instances running versions prior to 2026.1.2 using network scanning tools or Shodan.
  2. Obtain low-privileged credentials: Acquire any valid TeamCity user account (e.g., through phishing, credential stuffing, or use of a legitimate developer account).
  3. Authenticate to TeamCity: Log in to the TeamCity web interface or API using the low-privileged credentials.
  4. Identify target pipelines: Browse or enumerate build configurations and pipelines that the account should not have permission to modify.
  5. Send unauthorized modification request: Craft and submit API or web requests to pipeline management endpoints (e.g., REST API calls to modify build configurations) that bypass the missing authorization checks.
  6. Achieve objective: Inject malicious build steps (e.g., commands to exfiltrate secrets, deploy backdoors, or alter artifacts), effectively compromising the software supply chain or gaining access to sensitive pipeline data (GitHub Advisory, JetBrains).

Indicators of compromise

  • Logs: TeamCity audit logs showing pipeline or build configuration modifications by users who do not have explicit edit permissions for those projects; unexpected changes to build steps, triggers, or parameters logged under low-privileged accounts.
  • Network: Unusual REST API calls (e.g., PUT/POST to /app/rest/buildTypes/ or /app/rest/projects/ endpoints) originating from accounts not typically associated with pipeline administration.
  • File System: Unexpected or newly introduced build scripts, artifacts, or configuration files in build agent working directories that were not part of the original pipeline definition.
  • Process: Build agents executing unexpected commands or scripts introduced via tampered pipeline steps, such as outbound network connections, credential harvesting tools, or unauthorized file access.

Mitigation and workarounds

JetBrains has released a patch in TeamCity version 2026.1.2, which resolves the improper permission check. Organizations should upgrade to version 2026.1.2 or later as the primary remediation (JetBrains, GitHub Advisory). As an interim workaround, restrict TeamCity user access to trusted administrators only and audit recent pipeline modifications for unauthorized changes. Review and tighten role-based access controls within TeamCity to limit which users can view or modify build configurations.

Community reactions

Security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and VPNCentral covered the vulnerability as part of a broader JetBrains patch release addressing six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA (GBHackers, CyberSecurityNews, VPNCentral). Coverage was largely informational, noting the availability of the patch and the risk to CI/CD pipeline integrity. No significant researcher commentary or threat actor attribution has been reported at this time.

Additional resources


SourceThis report was generated using AI

Related JetBrains TeamCity vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59793HIGH8.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-49381MEDIUM4.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesMay 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management