Impact
JetBrains TeamCity suffered from an improper authorization check (CWE-862) that permits an attacker to alter build pipelines. This flaw allows unauthorized users to change pipeline configurations, compromising the integrity of the continuous integration/continuous delivery process and potentially introducing malicious code or bypassing quality controls.
Affected Systems
Any JetBrains TeamCity instance running a version earlier than 2026.1.2 is impacted. The vulnerability is not correctly enforced, regardless of the user’s overall role.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity risk. Its EPSS score of less than 1% indicates a very low probability of exploitation, and it is not listed in CISA KEV. The likely attack vector is the TeamCity web interface, where missing authorization checks allow an attacker who can authenticate to a user account that has been granted view access but not pipeline modification rights to elevate privileges and alter pipeline settings.
OpenCVE Enrichment