
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59796 is a missing authorization vulnerability in JetBrains TeamCity that allows authenticated low-privileged users to modify CI/CD pipelines beyond their intended permission scope. The flaw affects all TeamCity versions before 2026.1.2 and was disclosed on July 10, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, JetBrains).
The root cause is classified as CWE-862 (Missing Authorization), meaning the application fails to perform adequate authorization checks when a user attempts to access or modify pipeline resources. An authenticated attacker with low-level privileges can send crafted network requests to TeamCity's pipeline management endpoints, bypassing permission enforcement and altering build configurations or execution workflows they should not have access to. No user interaction is required, and the attack complexity is low, making it straightforward for any valid TeamCity account holder to exploit (GitHub Advisory).
Successful exploitation allows a low-privileged authenticated user to modify CI/CD pipeline configurations and build workflows beyond their authorized scope, resulting in high confidentiality and integrity impacts with no availability impact. An attacker could tamper with build scripts, inject malicious steps into pipelines, or access sensitive build artifacts and environment variables, potentially enabling supply chain compromise or lateral movement within the development infrastructure (GitHub Advisory, JetBrains).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.25–0.27%, placing it in the 19th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
/app/rest/buildTypes/ or /app/rest/projects/ from accounts with limited roles.JetBrains has released TeamCity version 2026.1.2, which addresses this vulnerability; upgrading to this version or later is the recommended remediation (JetBrains). As an interim workaround, administrators should restrict TeamCity user access to trusted administrators only and audit recent pipeline modification history for unauthorized changes. Reviewing and tightening role-based access control assignments within TeamCity projects can further reduce exposure until patching is complete.
The vulnerability was covered by several security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and VPNcentral as part of broader reporting on JetBrains patching six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA in July 2026 (GBHackers, CyberSecurityNews, VPNcentral). Community reaction was moderate, with attention focused on the pipeline tampering risk given TeamCity's role in CI/CD supply chains. No notable individual researcher commentary or vendor statements beyond the standard JetBrains security advisory page were identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."