Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-59796
JetBrains TeamCity vulnerability analysis and mitigation

Overview

CVE-2026-59796 is a missing authorization vulnerability in JetBrains TeamCity that allows authenticated low-privileged users to modify CI/CD pipelines beyond their intended permission scope. The flaw affects all TeamCity versions before 2026.1.2 and was disclosed on July 10, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, JetBrains).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the application fails to perform adequate authorization checks when a user attempts to access or modify pipeline resources. An authenticated attacker with low-level privileges can send crafted network requests to TeamCity's pipeline management endpoints, bypassing permission enforcement and altering build configurations or execution workflows they should not have access to. No user interaction is required, and the attack complexity is low, making it straightforward for any valid TeamCity account holder to exploit (GitHub Advisory).

Impact

Successful exploitation allows a low-privileged authenticated user to modify CI/CD pipeline configurations and build workflows beyond their authorized scope, resulting in high confidentiality and integrity impacts with no availability impact. An attacker could tamper with build scripts, inject malicious steps into pipelines, or access sensitive build artifacts and environment variables, potentially enabling supply chain compromise or lateral movement within the development infrastructure (GitHub Advisory, JetBrains).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable. The EPSS score is approximately 0.25–0.27%, placing it in the 19th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Exploitation steps

  1. Reconnaissance: Identify a JetBrains TeamCity instance running a version prior to 2026.1.2, accessible over the network. Obtain or compromise a low-privileged TeamCity user account.
  2. Authentication: Log in to the TeamCity instance using the low-privileged credentials to obtain a valid session token or API key.
  3. Identify target pipeline: Browse or enumerate available build configurations and pipelines, including those the low-privileged account should not have write access to.
  4. Craft unauthorized modification request: Send an authenticated HTTP request (e.g., REST API call or web UI form submission) targeting a pipeline configuration endpoint for a project outside the user's permission scope, exploiting the missing authorization check.
  5. Modify pipeline: Alter build steps, inject malicious scripts, change artifact paths, or modify environment variables within the target pipeline configuration.
  6. Trigger build: Optionally trigger a build run to execute the modified pipeline, potentially exfiltrating secrets, deploying malicious artifacts, or establishing persistence within the build environment (GitHub Advisory).

Indicators of compromise

  • Logs: TeamCity audit logs showing pipeline or build configuration modification events attributed to low-privileged user accounts that do not normally have write access to those projects; unexpected REST API calls to pipeline configuration endpoints from non-admin users.
  • Network: Unusual authenticated HTTP requests (PUT/POST) to TeamCity REST API endpoints such as /app/rest/buildTypes/ or /app/rest/projects/ from accounts with limited roles.
  • Application: Unexpected changes to build step definitions, added or modified build scripts, altered environment variable values, or new artifact publishing rules in pipelines not owned by the modifying user.
  • Process: Build agents executing unexpected scripts or commands introduced via tampered pipeline configurations.

Mitigation and workarounds

JetBrains has released TeamCity version 2026.1.2, which addresses this vulnerability; upgrading to this version or later is the recommended remediation (JetBrains). As an interim workaround, administrators should restrict TeamCity user access to trusted administrators only and audit recent pipeline modification history for unauthorized changes. Reviewing and tightening role-based access control assignments within TeamCity projects can further reduce exposure until patching is complete.

Community reactions

The vulnerability was covered by several security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and VPNcentral as part of broader reporting on JetBrains patching six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA in July 2026 (GBHackers, CyberSecurityNews, VPNcentral). Community reaction was moderate, with attention focused on the pipeline tampering risk given TeamCity's role in CI/CD supply chains. No notable individual researcher commentary or vendor statements beyond the standard JetBrains security advisory page were identified.

Additional resources


SourceThis report was generated using AI

Related JetBrains TeamCity vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65906CRITICAL10
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 23, 2026
CVE-2026-63077CRITICAL9.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
YesYesJul 27, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management