ZeroHour

CVE-2026-49373

large

Authenticated RCE in JetBrains TeamCity via Perforce Connection Settings

CVSS 3.1
8.8 high
EPSS
27%p98
Published
()
Modified
AI analysis

JetBrains TeamCity before 2026.1 is vulnerable to remote code execution through its handling of Perforce connection settings, an argument-injection flaw (CWE-88) in which attacker-controlled values are not properly neutralized when passed to OS-level commands. An attacker needs a low-privileged, authenticated account (per the CVSS PR:L metric) and can trigger the flaw by supplying malicious arguments in Perforce connection settings fields, causing the TeamCity server to execute arbitrary commands. Successful exploitation yields full server compromise with high impact to confidentiality, integrity, and availability, and TeamCity servers are particularly attractive targets because they store build pipelines, source-code credentials, and secrets. All deployments running any release prior to 2026.1 are affected, with the highest risk on internet-facing CI/CD servers that expose login to outside users. There is currently no known public proof-of-concept, the issue is not in CISA's KEV catalog, and no in-the-wild exploitation has been confirmed, though a 27.1% EPSS score (98th percentile) indicates a materially elevated likelihood of exploitation within the next 30 days.

What to do: Upgrade all TeamCity servers to version 2026.1 or later, as that is the first fixed release per the advisory. Until patched, restrict which accounts can create or edit Perforce connection settings, review existing Perforce connection configurations for tampering, and limit network exposure of TeamCity to trusted users; after upgrading, check logs for unexpected commands or logins associated with Perforce settings changes.

Affected
jetbrains teamcityall versions before 2026.1
Estimated exposure
largetens of thousands of internet-exposed TeamCity servers (order of magnitude 10k-100k; exact count of vulnerable deployments unknown) — Public internet-wide scans have historically shown on the order of tens of thousands of exposed TeamCity instances, and TeamCity is typically deployed once per organization as a central CI/CD server, so the affected population is plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

Vendors
jetbrains
Products
teamcity
Weakness
CWE-88
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.