JetBrains TeamCity Missing Authorization Vulnerability Allowing Unauthorized API Access

Vulnerability

A vulnerability exists in JetBrains TeamCity versions prior to 2026.12025.11.5, where authenticated users can inadvertently expose server API to unauthorized individuals. This issue arises from a lack of proper authorization checks, allowing sensitive API endpoints to be accessed without the necessary permissions.

Impact

Exploitation of this vulnerability could lead to unauthorized access to server API, allowing users to perform actions or retrieve data they are not entitled to.

Remediation

Users can update to TeamCity version 2026.1 or 2025.11.5, where this vulnerability has been addressed.

Added: May 11, 2026, 7:16 PM
Updated: May 11, 2026, 7:16 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
5.0
exploitability
5.2
remediation
7.7
relevance
8.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.