Impact
JetBrains TeamCity versions before 2026.1.2 allow an attacker to inject arbitrary client‑side script when agent‑reported data is displayed on the cloud profile page. The vulnerability is a stored cross‑site scripting flaw (CWE‑79) that results from improper escaping of the data rendered in the UI. It does not provide server‑side code execution or privilege escalation, but any script that runs in the victim’s browser can potentially read or modify page content, capture credentials, or perform other malicious activities during the session.
Affected Systems
Users operating JetBrains TeamCity cloud instances with a version older than 2026.1.2 are vulnerable. The issue manifests on the cloud profile page where agent data is rendered, so only instances that expose this page inbound to users are affected.
Risk and Exploitability
The CVSS score of 7.3 indicates a moderate‑to‑high risk. The EPSS score of less than 1 % shows an extremely low but nonzero probability that the vulnerability is actively exploited. The vulnerability is not listed in CISA KEV, suggesting no confirmed widespread exploitation. The likely attack vector involves an attacker who can influence agent‑reported data—such as by creating or modifying an agent—so that malicious content is stored and later rendered on the cloud profile page. This vector requires that the attacker has some level of access to agent configuration, but once the data is stored it can be rendered to any user who visits the profile page.
OpenCVE Enrichment