Description
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
Published: 2026-07-10
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains TeamCity suffered from an improper authorization check (CWE-862) that permits an attacker to alter build pipelines. This flaw allows unauthorized users to change pipeline configurations, compromising the integrity of the continuous integration/continuous delivery process and potentially introducing malicious code or bypassing quality controls.

Affected Systems

Any JetBrains TeamCity instance running a version earlier than 2026.1.2 is impacted. The vulnerability is not correctly enforced, regardless of the user’s overall role.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity risk. Its EPSS score of less than 1% indicates a very low probability of exploitation, and it is not listed in CISA KEV. The likely attack vector is the TeamCity web interface, where missing authorization checks allow an attacker who can authenticate to a user account that has been granted view access but not pipeline modification rights to elevate privileges and alter pipeline settings.

Generated by OpenCVE AI on July 26, 2026 at 13:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains TeamCity to version 2026.1.2 or later.
  • Configure the permission model so that only administrators or designated pipeline owners can edit pipeline configurations.
  • Perform an audit of all user roles and permissions to ensure that pipeline modification rights are limited to authorized personnel only.

Generated by OpenCVE AI on July 26, 2026 at 13:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Improper Permission Checks Enable Unauthorized Pipeline Modification in JetBrains TeamCity

Thu, 23 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Improper Permission Checks Allowing Unauthorized Pipeline Modification in JetBrains TeamCity

Sat, 18 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Improper Permission Checks Allowing Unauthorized Pipeline Modification in JetBrains TeamCity

Fri, 17 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Improper Permission Checks Allow Unauthorized Pipeline Modification in JetBrains TeamCity

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Improper Permission Checks Allow Unauthorized Pipeline Modification in JetBrains TeamCity

Mon, 13 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title TeamCity Pipeline Modification via Improper Permission Checks

Sat, 11 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title TeamCity Pipeline Modification via Improper Permission Checks

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains teamcity
Vendors & Products Jetbrains
Jetbrains teamcity

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Jetbrains Teamcity
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-14T03:55:42.656Z

Reserved: 2026-07-07T09:41:09.010Z

Link: CVE-2026-59796

cve-icon Vulnrichment

Updated: 2026-07-10T15:14:46.937Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T13:45:03Z

Weaknesses