CVE-2026-49373
largeAuthenticated RCE in JetBrains TeamCity via Perforce Connection Settings
JetBrains TeamCity before 2026.1 is vulnerable to remote code execution through its handling of Perforce connection settings, an argument-injection flaw (CWE-88) in which attacker-controlled values are not properly neutralized when passed to OS-level commands. An attacker needs a low-privileged, authenticated account (per the CVSS PR:L metric) and can trigger the flaw by supplying malicious arguments in Perforce connection settings fields, causing the TeamCity server to execute arbitrary commands. Successful exploitation yields full server compromise with high impact to confidentiality, integrity, and availability, and TeamCity servers are particularly attractive targets because they store build pipelines, source-code credentials, and secrets. All deployments running any release prior to 2026.1 are affected, with the highest risk on internet-facing CI/CD servers that expose login to outside users. There is currently no known public proof-of-concept, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been confirmed, though a 27.1% EPSS score (98th percentile) indicates a materially elevated likelihood of exploitation within the next 30 days.
What to do: Upgrade all TeamCity servers to version 2026.1 or later, as that is the first fixed release per the advisory. Until patched, restrict which accounts can create or edit Perforce connection settings, review existing Perforce connection configurations for tampering, and limit network exposure of TeamCity to trusted users; after upgrading, check logs for unexpected commands or logins associated with Perforce settings changes.
| jetbrains teamcity | all versions before 2026.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
- Vendors
- jetbrains
- Products
- teamcity
- Weakness
- CWE-88
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.