CVE-2026-59795
published 2026-07-10CVE-2026-59795: In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
PriorityP429medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.34%
26.2th percentile
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jetbrains | teamcity | < 2026.1.2 | 2026.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
JetBrains TeamCity up to 2026.1.1 Agent Registration cross site scripting (Nessus ID 327417)
vuldb·2026-07-18·CVSS 6.1
CVE-2026-59795 [MEDIUM] JetBrains TeamCity up to 2026.1.1 Agent Registration cross site scripting (Nessus ID 327417)
A vulnerability, which was classified as problematic, has been found in JetBrains TeamCity up to 2026.1.1. This affects an unknown part of the component Agent Registration. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-59795. The attack can be initiated remotely. There is not any exploit available.
GHSA
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
ghsa_unreviewed·2026-07-10
CVE-2026-59795 [HIGH] CWE-79 In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
No detection rules found.
No public exploits indexed.
2026-07-10
Published