JetBrains TeamCity SAML Plugin Insufficient Username Validation Vulnerability

Vulnerability

A vulnerability exists in JetBrains TeamCity versions prior to 2026.1, where the SAML plugin fails to properly validate usernames. This oversight could potentially be exploited to bypass authentication or authorization mechanisms.

Impact

Exploitation of this vulnerability could lead to unauthorized access or actions within TeamCity, by allowing users to manipulate SAML authentication processes.

Remediation

Users can update to TeamCity version 2026.1 or later, where this vulnerability has been addressed.

Added: May 29, 2026, 7:27 PM
Updated: May 29, 2026, 7:27 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
5.0
exploitability
7.4
remediation
7.7
relevance
9.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.