cbcvebase.

Jetbrains Teamcity vulnerabilities

276 known vulnerabilities affecting jetbrains/teamcity.

Total CVEs
276
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL27HIGH56MEDIUM184LOW9

Vulnerabilities

Page 1 of 14
CVE-2023-42793P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in 2023.05.42023-09-19
CVE-2023-42793 [CRITICAL] CWE-288 CVE-2023-42793: In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was p In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
nvd
CVE-2024-27198P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in 2023.11.42024-03-04
CVE-2024-27198 [CRITICAL] CWE-288 CVE-2024-27198: In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was p In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
nvd
CVE-2026-63077P1CRITICALCVSS 9.8KEVPoCfixed in 2025.11.7≥ 2026.1, < 2026.1.3+1 more2026-07-27
CVE-2026-63077 [CRITICAL] CWE-502 CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
nvd
CVE-2024-27199P1HIGHCVSS 7.3KEVPoCRansomwarefixed in 2023.11.42024-03-04
CVE-2024-27199 [HIGH] CWE-23 CVE-2024-27199: In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
nvd
CVE-2024-23917P1CRITICALCVSS 9.8ExploitedPoCfixed in 2023.11.32024-02-06
CVE-2024-23917 [CRITICAL] CWE-288 CVE-2024-23917: In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible
nvd
CVE-2019-15039P2CRITICALCVSS 9.8PoCv2018.2.42019-10-01
CVE-2019-15039 [CRITICAL] CWE-22 CVE-2019-15039: An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issu An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.
nvd
CVE-2026-49373P2HIGHCVSS 8.8fixed in 2026.12026-05-29
CVE-2026-49373 [HIGH] CWE-88 CVE-2026-49373: In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection setti In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
nvd
CVE-2021-31915P2CRITICALCVSS 9.8fixed in 2020.2.42021-05-11
CVE-2021-31915 [CRITICAL] CWE-78 CVE-2021-31915: In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was pos In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.
nvd
CVE-2021-31909P2CRITICALCVSS 9.8fixed in 2020.2.32021-05-11
CVE-2021-31909 [CRITICAL] CWE-88 CVE-2021-31909: In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possi In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.
nvd
CVE-2024-47949P3HIGHCVSS 7.5fixed in 2024.07.32024-10-08
CVE-2024-47949 [HIGH] CWE-23 CVE-2024-47949: In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary locatio In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
nvd
CVE-2022-25263P2CRITICALCVSS 9.8fixed in 2021.2.32022-02-25
CVE-2022-25263 [CRITICAL] CWE-78 CVE-2022-25263: JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.
nvd
CVE-2026-59793P2HIGHCVSS 8.8fixed in 2026.1.22026-07-10
CVE-2026-59793 [HIGH] CWE-73 CVE-2026-59793: In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integr In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
nvd
CVE-2019-18364P3CRITICALCVSS 9.8fixed in 2019.1.42019-10-31
CVE-2019-18364 [CRITICAL] CWE-502 CVE-2019-18364: In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
nvd
CVE-2021-43193P3CRITICALCVSS 9.8fixed in 2021.1.22021-11-09
CVE-2021-43193 [CRITICAL] CVE-2021-43193: In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is pos In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.
nvd
CVE-2026-65906P3CRITICALCVSS 10.0fixed in 2025.11.6≥ 2026.1, < 2026.1.2+1 more2026-07-23
CVE-2026-65906 [CRITICAL] CWE-94 CVE-2026-65906: In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was po In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
nvd
CVE-2021-31914P3CRITICALCVSS 9.8fixed in 2020.2.42021-05-11
CVE-2021-31914 [CRITICAL] CVE-2021-31914: In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was po In JetBrains TeamCity before 2020.2.4 on Windows, arbitrary code execution on TeamCity Server was possible.
nvd
CVE-2024-36470P3CRITICALCVSS 9.8fixed in 2022.04.7≥ 2022.10, < 2022.10.6+3 more2024-05-29
CVE-2024-36470 [CRITICAL] CWE-288 CVE-2024-36470: In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was po In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases
nvd
CVE-2025-46618P3MEDIUMCVSS 6.1fixed in 2025.03.12025-04-25
CVE-2025-46618 [MEDIUM] CWE-79 CVE-2025-46618: In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
nvd
CVE-2022-24331P3CRITICALCVSS 9.8fixed in 2021.42022-02-25
CVE-2022-24331 [CRITICAL] CVE-2022-24331: In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible. In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
nvd
CVE-2026-65907P3CRITICALCVSS 9.1fixed in 2026.1.2, 2025.11.62026-07-23
CVE-2026-65907 [CRITICAL] CWE-94 CVE-2026-65907: In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
nvd
1 / 14Next →
Jetbrains Teamcity vulnerabilities | cvebase