Impact
The vulnerability allows an attacker to see stored credentials embedded in thread names within JetBrains TeamCity. This exposure can reveal usernames, passwords, or authentication tokens that the platform uses, thereby compromising authentication data and potentially enabling unauthorized access to the system or other resources accessed with those credentials.
Affected Systems
JetBrains TeamCity versions older than 2026.1 are affected. Users running any release prior to 2026.1 should consider themselves exposed until the issue is resolved.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an adversary gaining access to thread dumps, logs, or other system introspection paths that reveal thread names, from which the exposed credentials can be extracted. This requires local or administrative access to the TeamCity instance but does not necessarily need remote exploitation.
OpenCVE Enrichment