Teamcity
This hub aggregates every CVE we track for Teamcity, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
269
CVEs tracked
17
Critical
36
High
3
In CISA KEV
Severity distribution
MEDIUM186HIGH36LOW30CRITICAL17
Monthly trend
8
5
0
5
0
9
3
2
3
3
4
5
11
3
3
0
0
11
0
3
0
0
12
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Teamcity.
- CVE-2026-49381In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible3.4
- CVE-2026-49380In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible3.1
- CVE-2026-49377In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters4.3
- CVE-2026-49379In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names6.5
- CVE-2026-49378In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion4.3
- CVE-2026-49375In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page6.1
- CVE-2026-49376In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin6.5
- CVE-2026-49374In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters7.6
- CVE-2026-49373In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings7.1
- CVE-2026-49372In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible7.5
- CVE-2026-49371In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible7.1
- CVE-2026-44413In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access8.2
- CVE-2026-28196In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk2.3
- CVE-2026-28195In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations4.3
- CVE-2026-28194In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow4.3
Product normalization is registry-driven with AI assist and human review. How it works