Jetbrains
Jetbrains Teamcity: vulnerabilidades y CVE
Jetbrains Teamcity tiene 279 vulnerabilidades publicadas, 36 de ellas en los últimos 12 meses. 28 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE279
Últimos 12 meses36
Críticas28
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-63077 | Crítica (9.8) | 90% | ⚠ Explotación activa | 27 jul 2026 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol |
| CVE-2024-27199 | Alta (7.3) | 100% | ⚠ Explotación activa | 4 mar 2024 | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible |
| CVE-2024-27198 | Crítica (9.8) | 100% | ⚠ Explotación activa | 4 mar 2024 | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible |
| CVE-2023-42793 | Crítica (9.8) | 100% | ⚠ Explotación activa | 19 sept 2023 | In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100255 | Crítica (9.8) | 0.35% | — | 30 sept 2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset |
| CVE-2026-100254 | Alta (8.8) | 0.46% | — | 30 sept 2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings |
| CVE-2026-100253 | Alta (8.8) | 0.43% | — | 30 sept 2026 | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL |
| CVE-2026-63077 | Crítica (9.8) | 90% | ⚠ Explotación activa | 27 jul 2026 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol |
| CVE-2026-65907 | Crítica (9.1) | 0.66% | — | 23 jul 2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible |
| CVE-2026-65906 | Crítica (10) | 0.66% | — | 23 jul 2026 | In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible |
| CVE-2026-59796 | Alta (8.1) | 0.35% | — | 10 jul 2026 | In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks |
| CVE-2026-59795 | Media (6.1) | 0.34% | — | 10 jul 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible |
| CVE-2026-59794 | Media (5.4) | 0.32% | — | 10 jul 2026 | In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data |
| CVE-2026-59793 | Alta (8.8) | 0.49% | — | 10 jul 2026 | In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration |
| CVE-2026-49381 | Media (4.8) | 0.29% | — | 29 may 2026 | In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible |
| CVE-2026-49380 | Media (6.1) | 0.23% | — | 29 may 2026 | In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible |
| CVE-2026-49379 | Media (6.5) | 0.34% | — | 29 may 2026 | In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names |
| CVE-2026-49378 | Media (4.3) | 0.29% | — | 29 may 2026 | In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion |
| CVE-2026-49377 | Media (4.3) | 0.92% | — | 29 may 2026 | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters |
| CVE-2026-49376 | Media (6.5) | 0.29% | — | 29 may 2026 | In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin |
| CVE-2026-49375 | Media (6.1) | 0.30% | — | 29 may 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page |
| CVE-2026-49374 | Alta (7.6) | 0.31% | — | 29 may 2026 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters |
| CVE-2026-49373 | Alta (8.8) | 0.60% | — | 29 may 2026 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings |
| CVE-2026-49372 | Alta (7.5) | 0.39% | — | 29 may 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible |
| CVE-2026-49371 | Alta (8.2) | 0.35% | — | 29 may 2026 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible |
| CVE-2026-44413 | Alta (7.5) | 0.34% | — | 11 may 2026 | In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access |
| CVE-2026-28196 | Baja (2.3) | 0.17% | — | 25 feb 2026 | In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk |
| CVE-2026-28195 | Media (4.3) | 0.26% | — | 25 feb 2026 | In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations |
| CVE-2026-28194 | Media (6.1) | 0.29% | — | 25 feb 2026 | In JetBrains TeamCity before 2025.11.3 open redirect was possible in the React project creation flow |
| CVE-2025-68268 | Media (6.1) | 0.21% | — | 16 dic 2025 | In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page |
| CVE-2025-68267 | Media (6.5) | 0.21% | — | 16 dic 2025 | In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token |
| CVE-2025-68166 | Media (6.1) | 0.20% | — | 16 dic 2025 | In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab |
| CVE-2025-68165 | Media (6.1) | 4.2% | — | 16 dic 2025 | In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup |
| CVE-2025-68164 | Baja (2.7) | 0.24% | — | 16 dic 2025 | In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.