Description
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
Published: 2026-05-29
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains TeamCity prior to version 2026.1 contains an insufficient username validation flaw in its SAML plugin. The weakness, labeled CWE‑863, allows inputs that are not properly verified against expected username patterns or values, potentially enabling an attacker to authenticate or impersonate legitimate users by submitting arbitrary or crafted usernames. The vulnerability could be leveraged to gain unauthorized system access, affecting confidentiality and integrity of TeamCity data depending on the attacker’s credentials. Without explicit details in the description, the scope is assumed to be full compromise if successful, though no denial of service impact is noted.

Affected Systems

All installations of JetBrains TeamCity released before 2026.1 are impacted. The flaw resides within the SAML authentication plugin, so any instance relying on SAML SSO and not updated to at least version 2026.1 is vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability. EPSS data is not available, so exploitation probability is not quantified, and the vulnerability is not currently listed in CISA’s KEV catalog. The known attack vector is the SAML authentication flow, which is accessible remotely by any user who can trigger a SAML login, making the exploit feasible for attackers with network access to the TeamCity service. Given the medium CVSS score and lack of known exploitation, the overall risk is moderate, but the potential for unauthorized access warrants prompt remediation.

Generated by OpenCVE AI on May 29, 2026 at 19:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains TeamCity to version 2026.1 or later, which includes the SAML username validation fix.
  • If upgrading immediately is not possible, temporarily disable the SAML authentication plugin to eliminate the vulnerable path until a patch can be applied.
  • Verify that the SAML service provider enforces strict username validation and does not allow arbitrary usernames; configure the plugin to reject any malformed or unexpected input.

Generated by OpenCVE AI on May 29, 2026 at 19:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 May 2026 20:00:00 +0000

Type Values Removed Values Added
Title Insufficient Username Validation in TeamCity SAML Plugin
First Time appeared Jetbrains
Jetbrains teamcity
Vendors & Products Jetbrains
Jetbrains teamcity

Fri, 29 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Jetbrains Teamcity
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-05-29T19:29:30.864Z

Reserved: 2026-05-29T18:07:57.110Z

Link: CVE-2026-49376

cve-icon Vulnrichment

Updated: 2026-05-29T19:29:25.572Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-29T19:16:27.537

Modified: 2026-05-29T20:11:15.977

Link: CVE-2026-49376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T19:45:06Z

Weaknesses