Description
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
Published: 2026-07-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains TeamCity versions prior to 2026.1.2 contain a flaw in the Perforce VCS integration that permits arbitrary file access, enabling the reading of any file located on the TeamCity server. This weakness is identified as CWE‑73.

Affected Systems

The affected product is JetBrains TeamCity, versions older than 2026.1.2. Users running TeamCity prior to the 2026.1.2 release are at risk.

Risk and Exploitability

The CVSS score of 8.8 classifies this issue as high severity. The EPSS score indicates a very low exploitation probability (less than 1 percent), and the vulnerability is not listed in the CISA KEV catalog. The description does not specify a precise attack path, so the likely attack vector is inferred to involve the Perforce integration interfaces.

Generated by OpenCVE AI on July 26, 2026 at 13:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest TeamCity patch or upgrade to version 2026.1.2 or newer
  • Restrict network access to the TeamCity server so that only trusted hosts can connect to the Perforce integration
  • Audit and monitor file access logs for unusual read patterns on the TeamCity server

Generated by OpenCVE AI on July 26, 2026 at 13:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Arbitrary File Access via Perforce Integration in JetBrains TeamCity

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title TeamCity Arbitrary File Access via Perforce Integration

Sat, 18 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title TeamCity Arbitrary File Access via Perforce Integration

Wed, 15 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title JetBrains TeamCity Perforce Integration Enables Arbitrary File Access

Mon, 13 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title JetBrains TeamCity Perforce Integration Enables Arbitrary File Access

Sun, 12 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Perforce VCS Integration Allows Arbitrary File Access in TeamCity

Sat, 11 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Perforce VCS Integration Allows Arbitrary File Access in TeamCity

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains teamcity
Vendors & Products Jetbrains
Jetbrains teamcity

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Jetbrains Teamcity
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-14T03:55:41.755Z

Reserved: 2026-07-07T09:41:07.789Z

Link: CVE-2026-59793

cve-icon Vulnrichment

Updated: 2026-07-10T15:18:58.747Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T13:45:03Z

Weaknesses
  • CWE-73

    External Control of File Name or Path