
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59796 is a missing authorization vulnerability in JetBrains TeamCity that allows authenticated low-privileged users to modify CI/CD pipelines beyond their intended permission scope. It affects all versions of JetBrains TeamCity before 2026.1.2 and was published on July 10, 2026. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, JetBrains).
The root cause is classified as CWE-862 (Missing Authorization): the application fails to perform adequate authorization checks when a user attempts to modify pipeline configurations, allowing privilege escalation within the platform's permission model. An attacker with a valid low-privileged TeamCity account can send crafted network requests to pipeline management endpoints, bypassing the expected permission boundaries to alter build configurations and execution workflows. No user interaction is required, and the attack complexity is low, making exploitation straightforward for any authenticated user (GitHub Advisory, JetBrains).
Successful exploitation allows a low-privileged authenticated attacker to tamper with CI/CD pipeline configurations and build workflows they are not authorized to access, resulting in high integrity and high confidentiality impact with no availability impact. An attacker could inject malicious build steps, exfiltrate secrets embedded in pipelines (e.g., API keys, credentials), redirect build artifacts, or sabotage software delivery processes. This could facilitate supply chain attacks or lateral movement within an organization's development infrastructure (GitHub Advisory, Feedly).
PUT/POST to /app/rest/buildTypes/ or /app/rest/projects/ endpoints) originating from accounts not typically associated with pipeline administration.JetBrains has released a patch in TeamCity version 2026.1.2, which resolves the improper permission check. Organizations should upgrade to version 2026.1.2 or later as the primary remediation (JetBrains, GitHub Advisory). As an interim workaround, restrict TeamCity user access to trusted administrators only and audit recent pipeline modifications for unauthorized changes. Review and tighten role-based access controls within TeamCity to limit which users can view or modify build configurations.
Security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and VPNCentral covered the vulnerability as part of a broader JetBrains patch release addressing six vulnerabilities across TeamCity, YouTrack, and IntelliJ IDEA (GBHackers, CyberSecurityNews, VPNCentral). Coverage was largely informational, noting the availability of the patch and the risk to CI/CD pipeline integrity. No significant researcher commentary or threat actor attribution has been reported at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."