Description
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
Published: 2026-07-10
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains TeamCity exposes a stored cross‑site scripting flaw (CWE‑79) that permits an attacker to register a build agent without authentication, embedding malicious script content into the agent’s metadata. This data is persisted and subsequently rendered by the Web interface when authorized users view agent information. Based on the nature of stored XSS, the injected script would execute in the browser context of those users, potentially enabling unauthorized actions or information disclosure.

Affected Systems

Any JetBrains TeamCity installation running a version earlier than 2026.1.2 is affected. No fixes exist for earlier versions except by upgrading to 2026.1.2 or newer.

Risk and Exploitability

The flaw carries a CVSS score of 8.1. The EPSS score is < 1 %, indicating a low likelihood of exploitation in the wild, and it is not listed in the CISA KEV catalog. An unauthenticated request to the agent‑registration API, where the attacker supplies crafted metadata containing script tags. Exploitation requires the vulnerable system to accept the registration and a legitimate user to subsequently view the stored metadata.

Generated by OpenCVE AI on July 26, 2026 at 13:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains TeamCity to version 2026.1.2 or a later patch release
  • If an upgrade is not immediately possible, block unauthenticated access to the agent‑registration endpoint or disable external agent connections
  • Apply web‑application‑firewall rules that filter out script content in registration requests until a vendor patch is applied

Generated by OpenCVE AI on July 26, 2026 at 13:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting via Unauthenticated Build Agent Registration in JetBrains TeamCity

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Stored XSS via Unauthenticated Agent Registration in JetBrains TeamCity

Tue, 21 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Stored XSS via Unauthenticated Agent Registration in JetBrains TeamCity

Fri, 17 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Agent Registration Stored XSS in JetBrains TeamCity

Wed, 15 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Agent Registration Stored XSS in JetBrains TeamCity

Tue, 14 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Unauthenticated Agent Registration in JetBrains TeamCity

Mon, 13 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Unauthenticated Agent Registration in JetBrains TeamCity

Sun, 12 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting via Unauthenticated Agent Registration in JetBrains TeamCity

Sat, 11 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting via Unauthenticated Agent Registration in JetBrains TeamCity

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains teamcity
Vendors & Products Jetbrains
Jetbrains teamcity

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Jetbrains Teamcity
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-10T16:59:47.774Z

Reserved: 2026-07-07T09:41:08.700Z

Link: CVE-2026-59795

cve-icon Vulnrichment

Updated: 2026-07-10T15:17:53.828Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T13:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')