JetBrains TeamCity Sensitive Data Exposure Vulnerability via Default Agent Parameters

Vulnerability

A vulnerability in JetBrains TeamCity prior to version 2025.11.2 allows for the exposure of sensitive data through default agent parameters. This issue could lead to unauthorized access to confidential information, potentially including credentials or other private data.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive data, including credentials, which could be misused to gain additional privileges or access within the application or system.

Remediation

Users can update to JetBrains TeamCity version 2025.11.2 or later to address this vulnerability.

Added: May 29, 2026, 7:26 PM
Updated: May 29, 2026, 7:26 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
9.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.