JetBrains TeamCity Credentials Exposure Vulnerability via Parameter Autocompletion

Vulnerability

A vulnerability exists in JetBrains TeamCity versions prior to 2026.1, where credential parameters were inadvertently exposed through parameter autocompletion. This issue could lead to unauthorized visibility of sensitive information.

Impact

Exposed credentials could be accessed by unauthorized users, potentially leading to further exploitation or unauthorized actions within the application.

Remediation

Users can update to TeamCity version 2026.1 or later to address this vulnerability.

Added: May 29, 2026, 7:26 PM
Updated: May 29, 2026, 7:26 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.