In JetBrains YouTrack before 2026
Description
In JetBrains YouTrack before 2026
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
18 vulnerabilities from JetBrains
← Back to all CVEsIn JetBrains YouTrack before 2026
In JetBrains YouTrack before 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In JetBrains YouTrack before 2026
In JetBrains YouTrack before 2026
---METADATA---
VENDOR: JetBrains
PRODUCT: YouTrack
AFFECTED_VERSIONS: < 2026.2.18068
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A stored cross-site scripting vulnerability exists in JetBrains YouTrack, allowing remote attackers to execute arbitrary scripts in the context of a user session.
Executive Summary:
A cross-site scripting vulnerability in JetBrains YouTrack allows for potential unauthorized script execution and information disclosure within the application environment.
Vulnerability Details
CVE-ID: CVE-2026-75048
Affected Software: JetBrains YouTrack
Affected Versions: < 2026.2.18068
Vulnerability: The application is affected by a cross-site scripting (CWE-79) vulnerability. An unauthenticated attacker can leverage this flaw via a crafted interaction to execute malicious scripts in the context of a victim's session.
Business Impact
This vulnerability poses a significant risk to data confidentiality and integrity, as attackers could potentially steal session tokens or perform actions on behalf of authenticated users. With a CVSS score of 8.2, the potential for unauthorized access to project management data warrants immediate attention to protect sensitive organizational information.
Remediation Plan
Immediate Action: Upgrade to JetBrains YouTrack version 2026.2.18068 or later.
Proactive Monitoring: Review web access logs and application audit trails for anomalous patterns indicative of XSS attempts, such as unusual URL parameters or script-like characters.
Compensating Controls: Implement a strong Content Security Policy (CSP) to mitigate the impact of potential cross-site scripting attacks.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of August 18, 2026, there is no public information indicating active exploitation or a public proof of concept for this vulnerability. The vulnerability requires user interaction to facilitate the attack.
Analyst Recommendation
Due to the severity of cross-site scripting in a collaborative environment like YouTrack, administrators should prioritize the application of the vendor-provided security update. Ensuring all users are on the latest version is critical to maintaining the security of the platform.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In JetBrains YouTrack before 2025
In JetBrains YouTrack before 2025
---METADATA---
VENDOR: JetBrains
PRODUCT: YouTrack
AFFECTED_VERSIONS: 0 up to (excluding) 2025.3.156085, 2026.1.13914, 2026.2.18095
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
JetBrains YouTrack is affected by an access control vulnerability. This flaw allows authenticated users to perform unauthorized actions, leading to potential data or system compromise.
Executive Summary:
An access control vulnerability in JetBrains YouTrack, identified as CWE-862, requires immediate patching to prevent unauthorized administrative actions.
Vulnerability Details
CVE-ID: CVE-2026-75044
Affected Software: JetBrains YouTrack
Affected Versions: 0 up to (excluding) 2025.3.156085, 2026.1.13914, 2026.2.18095
Vulnerability: The vulnerability is an improper authorization flaw (CWE-862) that allows an authenticated user to perform actions beyond their assigned privileges. It occurs during standard application usage and does not require elevated access to initiate.
Business Impact
The ability to bypass authorization checks can lead to unauthorized data access, modification, or destruction of project management information. With a CVSS score of 8.1, this represents a major security risk that could result in severe operational disruption or the compromise of sensitive organizational data within YouTrack.
Remediation Plan
Immediate Action: Update YouTrack to the corresponding fixed version: 2025.3.156085, 2026.1.13914, or 2026.2.18095, depending on the current branch.
Proactive Monitoring: Audit user activity logs to identify suspicious permission escalations or unauthorized configuration changes made by standard users.
Compensating Controls: Implement strict role-based access control (RBAC) and limit user permissions to the absolute minimum required for their roles until the update is applied.
Exploitation Status
Public Exploit Available: No confirmed public exploit available.
Analyst Notes: As of August 18, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. Authorization bypasses are high-value targets for attackers seeking to move laterally within internal systems.
Analyst Recommendation
Organizations should prioritize the update to the specified versions of YouTrack. Ensuring that all users are operating on patched software is the only reliable way to remediate this authorization vulnerability and protect the integrity of your project management assets.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In JetBrains TeamCity before 2026
In JetBrains TeamCity before 2026
---METADATA---
VENDOR: JetBrains
PRODUCT: TeamCity
AFFECTED_VERSIONS: JetBrains TeamCity: 0 up to (excluding) 2026.1.2, 2025.11.6
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
JetBrains TeamCity is vulnerable to code injection (CWE-94) in versions prior to 2026.1.2 and 2025.11.6, potentially allowing authenticated attackers to execute arbitrary code.
Executive Summary:
A code injection vulnerability in JetBrains TeamCity allows authenticated attackers to achieve remote code execution, posing a significant risk to build infrastructure integrity.
Vulnerability Details
CVE-ID: CVE-2026-65906
Affected Software: JetBrains TeamCity
Affected Versions: JetBrains TeamCity: 0 up to (excluding) 2026.1.2, 2025.11.6
Vulnerability: This vulnerability involves improper control of generation of code (CWE-94), which can be triggered by an attacker with low privileges. The vulnerability requires authenticated access to the TeamCity instance to perform malicious actions.
Business Impact
Successful exploitation allows an attacker to execute arbitrary code within the context of the TeamCity server. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to full system compromise, unauthorized access to sensitive build artifacts, and potential lateral movement into the development pipeline.
Remediation Plan
Immediate Action: Update JetBrains TeamCity to version 2026.1.2, 2025.11.6, or the latest available release provided by the vendor.
Proactive Monitoring: Review TeamCity server access logs for suspicious activity, particularly requests involving configuration changes or unexpected script execution.
Compensating Controls: Restrict network access to the TeamCity interface to trusted IP ranges and ensure the service runs with the minimum necessary privileges to limit the impact of a potential breach.
Exploitation Status
Public Exploit Available: No (exploit_available: unknown)
Analyst Notes: As of July 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to the potential for code injection, which often provides a direct path to server compromise.
Analyst Recommendation
The high CVSS score of 8.8 underscores the urgency of addressing this vulnerability. Administrators should prioritize patching their TeamCity instances immediately to prevent unauthorized code execution and maintain the integrity of their software development life cycle.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In JetBrains WebStorm before 2026
In JetBrains WebStorm before 2026
---METADATA---
VENDOR: JetBrains
PRODUCT: WebStorm
AFFECTED_VERSIONS: 0 up to (excluding) 2026.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
JetBrains WebStorm is vulnerable to inclusion of functionality from an untrusted control sphere, which could lead to unauthorized code execution.
Executive Summary:
A high-severity vulnerability in JetBrains WebStorm allows for potential unauthorized code execution, necessitating an immediate software update.
Vulnerability Details
CVE-ID: CVE-2026-64807
Affected Software: JetBrains WebStorm
Affected Versions: 0 up to (excluding) 2026.2
Vulnerability: This issue is classified as CWE-829, which involves the inclusion of functionality from an untrusted control sphere. The attack requires user interaction and may be leveraged by an unauthenticated attacker to gain significant control over the application environment.
Business Impact
The CVSS score of 7.8 underscores the critical nature of this vulnerability for development teams. Successful exploitation could allow an attacker to bypass security controls, leading to the compromise of sensitive development environments and potential downstream impacts on software deliverables.
Remediation Plan
Immediate Action: Upgrade to JetBrains WebStorm version 2026.2 or later to address the underlying security flaw.
Proactive Monitoring: Review application and system logs for unauthorized configuration changes or unexpected script execution within the WebStorm environment.
Compensating Controls: Implement strict file permission policies and use security software to monitor for unauthorized modifications to IDE configuration files or plugins.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability requires the user to perform an action, which serves as a necessary condition for successful exploitation.
Analyst Recommendation
The risk associated with this vulnerability is significant for organizations relying on WebStorm. Administrators must ensure that all instances are patched to version 2026.2 to mitigate the risk of unauthorized code execution and maintain the integrity of their development environment.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In JetBrains WebStorm before 2026
In JetBrains WebStorm before 2026
---METADATA---
VENDOR: JetBrains
PRODUCT: WebStorm
AFFECTED_VERSIONS: JetBrains WebStorm 0 up to (excluding) 2026.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A vulnerability in JetBrains WebStorm allows for potential unauthorized access or system compromise due to improper inclusion of control functionality.
Executive Summary:
A high-severity vulnerability in JetBrains WebStorm versions prior to 2026.2 exposes the application to potential compromise of confidentiality, integrity, and availability.
Vulnerability Details
CVE-ID: CVE-2026-64806
Affected Software: JetBrains WebStorm
Affected Versions: JetBrains WebStorm 0 up to (excluding) 2026.2
Vulnerability: This is an inclusion of functionality from an untrusted control sphere (CWE-829). The vulnerability can be exploited by an unauthenticated local attacker to achieve full system impact.
Business Impact
The vulnerability carries a CVSS score of 8.4, which indicates a high risk to business operations. Successful exploitation could allow an attacker to gain unauthorized access to the local development environment, potentially leading to the theft of proprietary source code, credentials, or the execution of arbitrary code with the privileges of the user running the software.
Remediation Plan
Immediate Action: Update JetBrains WebStorm to version 2026.2 or later immediately to resolve this security flaw.
Proactive Monitoring: Review system logs for unauthorized access or unusual process execution within the development environment.
Compensating Controls: Ensure that the local system is protected by endpoint security solutions and restrict local access to authorized users only.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of July 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw's high CVSS score is driven by the potential for total impact on confidentiality, integrity, and availability.
Analyst Recommendation
Given the severity of this vulnerability, it is imperative that organizations using JetBrains WebStorm prioritize the upgrade to version 2026.2. Failure to patch may expose development environments to significant security risks.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In JetBrains WebStorm before 2026
In JetBrains WebStorm before 2026
---METADATA---
VENDOR: JetBrains
PRODUCT: WebStorm
AFFECTED_VERSIONS: 0 up to (excluding) 2026.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A vulnerability in JetBrains WebStorm versions prior to 2026.2 allows for the inclusion of untrusted functionality, which could potentially lead to unauthorized system actions.
Executive Summary:
JetBrains WebStorm versions before 2026.2 are affected by a security flaw involving the inclusion of untrusted components, presenting a high risk to the development environment.
Vulnerability Details
CVE-ID: CVE-2026-64805
Affected Software: JetBrains WebStorm
Affected Versions: 0 up to (excluding) 2026.2
Vulnerability: This issue is identified as CWE-829, involving the inclusion of functionality from an untrusted control sphere. The vulnerability allows for exploitation by an attacker without requiring specific authentication, based on the provided CVSS vector.
Business Impact
Exploitation of this vulnerability could lead to significant security breaches within the development workstation, potentially resulting in the loss of proprietary source code or credentials. The CVSS score of 8.4 underscores the high severity and the need for immediate remediation to protect organizational assets.
Remediation Plan
Immediate Action: Upgrade all installations of JetBrains WebStorm to version 2026.2 or the latest available release.
Proactive Monitoring: Audit logs for unusual activity or unauthorized component loading within the WebStorm environment.
Compensating Controls: Apply strict network and host-based access controls to limit the potential impact if a developer workstation is compromised.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. While exploitation has not been confirmed, the nature of the flaw suggests that it could be weaponized by sophisticated actors targeting software supply chains.
Analyst Recommendation
Security teams should enforce the update to version 2026.2 across all developer machines immediately. Addressing this vulnerability is critical to maintaining a secure development environment and preventing potential downstream impacts to production code.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In JetBrains GoLand before 2026
In JetBrains GoLand before 2026
---METADATA---
VENDOR: JetBrains
PRODUCT: GoLand
AFFECTED_VERSIONS: 0 up to (excluding) 2026.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
JetBrains GoLand contains a code injection vulnerability that may allow for arbitrary code execution if a user is induced to process malicious data.
Executive Summary:
A high-severity code injection vulnerability in JetBrains GoLand could allow unauthorized attackers to execute arbitrary code on the affected system.
Vulnerability Details
CVE-ID: CVE-2026-64803
Affected Software: JetBrains GoLand
Affected Versions: 0 up to (excluding) 2026.2
Vulnerability: This flaw is identified as CWE-94, involving improper control of code generation. It requires user interaction and can be exploited by an unauthenticated attacker to achieve complete control over the affected process.
Business Impact
With a CVSS score of 7.8, this vulnerability poses a substantial threat to the security of development workstations. Exploitation could result in the exfiltration of sensitive credentials or proprietary source code, potentially leading to supply chain compromise and significant business disruption.
Remediation Plan
Immediate Action: Apply the vendor security update by upgrading to JetBrains GoLand version 2026.2 or newer.
Proactive Monitoring: Monitor developer workstations for anomalous outbound network connections or unexpected system behavior following the opening of untrusted projects.
Compensating Controls: Restrict the execution of unknown or untrusted project files within the IDE and enforce endpoint detection and response (EDR) policies to limit the impact of potential code execution.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 24, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is highly dependent on user interaction to trigger the malicious payload.
Analyst Recommendation
Due to the severity of the potential impact, rapid deployment of the latest security update is essential. Security teams should verify that all installations of GoLand are updated to version 2026.2 to ensure the vulnerability is fully remediated.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
---METADATA---
VENDOR: JetBrains
PRODUCT: TeamCity
AFFECTED_VERSIONS: 0 up to (excluding) 2026.1.3, 2025.11.7
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
Executive Summary:
A critical vulnerability in JetBrains TeamCity allows unauthenticated remote attackers to execute arbitrary code via the agent polling protocol.
Vulnerability Details
CVE-ID: CVE-2026-63077
Affected Software: JetBrains TeamCity
Affected Versions: 0 up to (excluding) 2026.1.3, 2025.11.7
Vulnerability: This is a deserialization vulnerability (CWE-502) in the agent polling protocol. The vulnerability allows unauthenticated remote attackers to achieve remote code execution, as indicated by the CVSS vector AV:N/PR:N.
Business Impact
With a CVSS score of 9.8, this vulnerability presents a severe risk to CI/CD pipelines. Successful exploitation could allow an attacker to compromise build artifacts, steal source code, or gain persistent access to the internal network.
Remediation Plan
Immediate Action: Upgrade JetBrains TeamCity to version 2026.1.3, 2025.11.7, or the latest available version immediately.
Proactive Monitoring: Review audit logs for unexpected connections to the agent polling port and monitor for unauthorized process creation on the TeamCity server.
Compensating Controls: Restrict network access to the TeamCity agent polling interface using firewall rules or network segmentation to ensure only authorized build agents can communicate with the server.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of July 27, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is highly automatable, which increases the likelihood of exploitation by opportunistic attackers.
Analyst Recommendation
Organizations using JetBrains TeamCity should treat this as a high-priority security event. Upgrading to the patched version is essential to secure the development environment and protect against unauthorized access to code repositories and build infrastructure.
Update JetBrains TeamCity to the latest version. Check the vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
Deadline: August 8, 2026
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
JetBrains YouTrack is affected by an authentication bypass vulnerability allowing unauthenticated attackers to gain administrative access via direct d...
JetBrains YouTrack is affected by an authentication bypass vulnerability allowing unauthenticated attackers to gain administrative access via direct database manipulation.
---METADATA---
VENDOR: JetBrains
PRODUCT: YouTrack
AFFECTED_VERSIONS: 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 (and all versions prior)
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
JetBrains YouTrack is affected by an authentication bypass vulnerability allowing unauthenticated attackers to gain administrative access via direct database manipulation.
Executive Summary:
A critical authentication bypass vulnerability in JetBrains YouTrack allows unauthenticated remote attackers to gain full administrative control over the application.
Vulnerability Details
CVE-ID: CVE-2026-62422
Affected Software: JetBrains YouTrack
Affected Versions: All versions prior to 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, and 2024.2.148429.
Vulnerability: This is an authentication bypass vulnerability categorized as CWE-306, where an attacker can achieve administrative privileges without valid credentials by exploiting direct database access paths. The vulnerability is remotely exploitable without requiring user interaction.
Business Impact
The potential for unauthorized administrative access poses a catastrophic risk to business operations, as attackers could modify project data, exfiltrate sensitive information, or disrupt service availability. Given the CVSS score of 10.0, this vulnerability represents the highest level of severity and necessitates immediate remediation to prevent complete system compromise.
Remediation Plan
Immediate Action: Upgrade your YouTrack installation to the latest version corresponding to your release branch as specified by JetBrains.
Proactive Monitoring: Review system access logs for anomalous database interactions or unexpected administrative login events.
Compensating Controls: Ensure the YouTrack instance is not exposed to the public internet and restrict access to the underlying database server to authorized internal IP addresses only.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 14, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is inherently dangerous due to the total bypass of authentication mechanisms.
Analyst Recommendation
This vulnerability is critical and represents an urgent threat to any organization utilizing JetBrains YouTrack. Administrators should prioritize patching immediately to eliminate the risk of total unauthorized administrative takeover.
Update JetBrains YouTrack to the latest version. Check the vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
In JetBrains TeamCity before 2026
In JetBrains TeamCity before 2026
---METADATA---
VENDOR: JetBrains
PRODUCT: TeamCity
AFFECTED_VERSIONS: 0 up to (excluding) 2026.1.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
JetBrains TeamCity contains an improper authorization vulnerability (CWE-862) that may allow an authenticated user to perform unauthorized actions.
Executive Summary:
An improper authorization flaw in JetBrains TeamCity allows authenticated users to exceed their defined privileges, posing a risk of unauthorized system modification.
Vulnerability Details
CVE-ID: CVE-2026-59796
Affected Software: JetBrains TeamCity
Affected Versions: 0 up to (excluding) 2026.1.2
Vulnerability: This is an improper authorization vulnerability where the application fails to adequately verify the permissions of an authenticated user. This allows a standard authenticated user to perform actions typically reserved for higher-privileged roles.
Business Impact
Successful exploitation could result in full unauthorized access to sensitive build configurations, project settings, or administrative functions. With a CVSS score of 8.1, this vulnerability presents a critical risk to the security posture of the development environment, potentially allowing attackers to inject malicious code into build artifacts.
Remediation Plan
Immediate Action: Update all instances of JetBrains TeamCity to version 2026.1.2 to resolve the missing authorization checks.
Proactive Monitoring: Review access control logs and audit trails to identify any suspicious activity where users are accessing functions outside their standard scope.
Compensating Controls: Enforce strict Role-Based Access Control (RBAC) and ensure that administrative interfaces are restricted to trusted network segments.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 11, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Administrators should apply the vendor-provided patch immediately. Given that this vulnerability allows for privilege escalation, it is imperative to verify that all user roles are correctly configured after the update is applied.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In JetBrains TeamCity before 2026
In JetBrains TeamCity before 2026
---METADATA---
VENDOR: JetBrains
PRODUCT: TeamCity
AFFECTED_VERSIONS: 0 up to (excluding) 2026.1.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
JetBrains TeamCity is vulnerable to Cross-Site Scripting (CWE-79), potentially allowing an attacker to execute arbitrary scripts in a user's browser.
Executive Summary:
A Cross-Site Scripting vulnerability in JetBrains TeamCity could allow unauthorized script execution, posing a significant risk to user session integrity.
Vulnerability Details
CVE-ID: CVE-2026-59795
Affected Software: JetBrains TeamCity
Affected Versions: 0 up to (excluding) 2026.1.2
Vulnerability: This vulnerability is a Cross-Site Scripting (XSS) flaw. The attack vector is network-based and requires user interaction, where an attacker could trick a user into executing malicious JavaScript within the context of the TeamCity interface.
Business Impact
The exploitation of this vulnerability could lead to session hijacking, unauthorized actions performed on behalf of a logged-in user, or the exfiltration of sensitive information. Given the CVSS score of 8.1, the high impact on confidentiality and integrity necessitates immediate attention to prevent potential compromise of build pipelines and administrative accounts.
Remediation Plan
Immediate Action: Upgrade JetBrains TeamCity to version 2026.1.2 or later as specified in the vendor security advisory.
Proactive Monitoring: Monitor application logs for unusual request patterns, particularly those involving script tags or unexpected URL parameters.
Compensating Controls: Implement a strict Content Security Policy (CSP) and utilize a Web Application Firewall (WAF) to filter malicious payloads from incoming web traffic.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 11, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Organizations utilizing JetBrains TeamCity must prioritize patching to version 2026.1.2. Failure to remediate this issue exposes the CI/CD environment to significant risk of manipulation and data theft.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In JetBrains TeamCity before 2026
In JetBrains TeamCity before 2026
---METADATA---
VENDOR: JetBrains
PRODUCT: TeamCity
AFFECTED_VERSIONS: 0 up to (excluding) 2026.1.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
JetBrains TeamCity contains a Cross-Site Scripting (XSS) vulnerability allowing authenticated users with low privileges to execute malicious scripts in the context of the application.
Executive Summary:
An authenticated Cross-Site Scripting (XSS) vulnerability in JetBrains TeamCity may allow unauthorized script execution within the application context.
Vulnerability Details
CVE-ID: CVE-2026-59794
Affected Software: JetBrains TeamCity
Affected Versions: 0 up to (excluding) 2026.1.2
Vulnerability: The application is susceptible to Cross-Site Scripting (CWE-79), which can be triggered by authenticated users with low privileges. This flaw allows for the injection of malicious client-side scripts that execute when viewed by other users, including administrators.
Business Impact
With a CVSS score of 7.3 (High), this vulnerability poses a significant risk to organizational security. Successful exploitation could lead to session hijacking, unauthorized actions performed on behalf of legitimate users, and potential compromise of sensitive CI/CD pipeline configurations.
Remediation Plan
Immediate Action: Upgrade to TeamCity version 2026.1.2 or later as specified by the vendor.
Proactive Monitoring: Review web server and application audit logs for unusual script injections or unexpected URL parameters associated with user profile updates or build configurations.
Compensating Controls: Deploy a Web Application Firewall (WAF) with robust XSS filtering rules to inspect and sanitize incoming HTTP requests, providing a layer of protection until the update can be deployed.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of July 12, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw requires an authenticated session, which limits the attack surface to existing users.
Analyst Recommendation
Given the High severity rating and the potential for lateral movement within the development environment, administrators should prioritize updating TeamCity instances. Patching is the only effective way to neutralize the underlying vulnerability in the application logic.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In JetBrains TeamCity before 2026
In JetBrains TeamCity before 2026
---METADATA---
VENDOR: JetBrains
PRODUCT: TeamCity
AFFECTED_VERSIONS: 0 up to (excluding) 2026.1.2
CONFIDENCE: high
MISSING: technical_details
---END_METADATA---
Description Summary:
JetBrains TeamCity contains a vulnerability related to external control of file name or path, impacting versions prior to 2026.1.2.
Executive Summary:
A high-severity vulnerability in JetBrains TeamCity allows authenticated attackers to potentially compromise the integrity or confidentiality of the build server.
Vulnerability Details
CVE-ID: CVE-2026-59793
Affected Software: JetBrains TeamCity
Affected Versions: 0 up to (excluding) 2026.1.2
Vulnerability: The vulnerability is classified as CWE-73 (External Control of File Name or Path), which may allow an authenticated attacker to manipulate file paths. This often leads to unauthorized file access or modification within the TeamCity environment.
Business Impact
With a CVSS score of 8.8, this flaw represents a significant risk to the CI/CD pipeline. Unauthorized access to build configurations, source code, or deployment artifacts can lead to supply chain compromise, where an attacker could inject malicious code into production software builds.
Remediation Plan
Immediate Action: Update all JetBrains TeamCity instances to version 2026.1.2 or later to mitigate the path manipulation vulnerability.
Proactive Monitoring: Monitor access logs for anomalous file path requests or attempts to access configuration directories outside of standard user scope.
Compensating Controls: Restrict access to the TeamCity administrative interface to trusted internal networks and employ WAF rules to detect directory traversal attempts.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 11, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Given TeamCity's central role in the software development lifecycle, this vulnerability must be treated with high priority. Organizations should verify their current deployment version and apply the update to 2026.1.2 immediately to prevent potential pipeline contamination.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
JetBrains Hub is susceptible to privilege escalation by allowing the attachment of unauthorized authentication details to user accounts.
JetBrains Hub is susceptible to privilege escalation by allowing the attachment of unauthorized authentication details to user accounts.
---METADATA---
VENDOR: JetBrains
PRODUCT: Hub
AFFECTED_VERSIONS: Before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429
---END_METADATA---
Description Summary:
JetBrains Hub is susceptible to privilege escalation by allowing the attachment of unauthorized authentication details to user accounts.
Executive Summary:
A critical privilege escalation vulnerability in JetBrains Hub allows attackers to manipulate authentication details to gain elevated account permissions.
Vulnerability Details
CVE-ID: CVE-2026-56142
Affected Software: JetBrains Hub
Affected Versions: Before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429
Vulnerability: The flaw enables privilege escalation by allowing the unauthorized association of authentication metadata with existing accounts. This effectively bypasses standard authorization checks to grant unauthorized users elevated access.
Business Impact
This vulnerability enables attackers to escalate their privileges to administrative levels, potentially leading to unauthorized data access and system-wide modifications. With a CVSS score of 9.9, the business impact is severe, threatening the integrity of the entire user directory and associated project management systems.
Remediation Plan
Immediate Action: Update JetBrains Hub to the latest version to patch the privilege escalation mechanism.
Proactive Monitoring: Review user account modification logs for suspicious activity, specifically looking for unexpected changes to authentication providers or account metadata.
Compensating Controls: Implement strict multi-factor authentication (MFA) and monitor for anomalous login patterns to detect potential abuse of escalated accounts.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of Jun 19, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Privilege escalation vulnerabilities are frequently targeted to maintain persistence within a network. It is imperative that administrators update to the latest patched version of JetBrains Hub immediately to ensure the security of account management and authorization controls.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
JetBrains Hub contains an authentication bypass vulnerability via direct database access that allows unauthorized administrative control.
JetBrains Hub contains an authentication bypass vulnerability via direct database access that allows unauthorized administrative control.
---METADATA---
VENDOR: JetBrains
PRODUCT: Hub
AFFECTED_VERSIONS: Before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429
---END_METADATA---
Description Summary:
JetBrains Hub contains an authentication bypass vulnerability via direct database access that allows unauthorized administrative control.
Executive Summary:
A critical authentication bypass vulnerability in JetBrains Hub allows unauthenticated attackers to gain full administrative access to the platform.
Vulnerability Details
CVE-ID: CVE-2026-50242
Affected Software: JetBrains Hub
Affected Versions: Before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429
Vulnerability: This vulnerability involves an authentication bypass flaw triggered by direct database access. It permits an unauthenticated attacker to assume administrative privileges within the application.
Business Impact
The potential for unauthorized administrative access poses a catastrophic risk to organizational data integrity and confidentiality. Given the CVSS score of 10.0, this vulnerability could lead to complete system compromise, allowing attackers to modify configurations, extract sensitive user data, or deploy malicious payloads across the enterprise environment.
Remediation Plan
Immediate Action: Upgrade all instances of JetBrains Hub to the specified patched versions or higher immediately.
Proactive Monitoring: Review database access logs for unusual queries or unauthorized connection attempts originating from non-standard internal assets.
Compensating Controls: Restrict network-level access to the underlying database port to authorized management hosts only as a temporary mitigation.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of Jun 19, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
This vulnerability represents the highest level of risk to JetBrains Hub deployments. Administrators must prioritize patching this flaw immediately to prevent total administrative takeover. Failure to remediate will leave the identity and access management infrastructure exposed to full compromise.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
JetBrains Hub versions prior to 2025.3.119807 contain an authentication bypass vulnerability that allows unauthenticated attackers to perform administ...
JetBrains Hub versions prior to 2025.3.119807 contain an authentication bypass vulnerability that allows unauthenticated attackers to perform administrative actions.
---METADATA---
VENDOR: JetBrains
PRODUCT: Hub
AFFECTED_VERSIONS: Prior to 2025.3.119807
---END_METADATA---
Description Summary:
JetBrains Hub versions prior to 2025.3.119807 contain an authentication bypass vulnerability that allows unauthenticated attackers to perform administrative actions.
Executive Summary:
An authentication bypass in JetBrains Hub allows unauthenticated remote attackers to gain administrative control over the platform, compromising all managed user accounts and integrations.
Vulnerability Details
CVE-ID: CVE-2026-25848
Affected Software: JetBrains Hub
Affected Versions: Prior to 2025.3.119807
Vulnerability: The vulnerability allows an unauthenticated attacker to bypass the standard login process. Once bypassed, the attacker can perform actions with administrative privileges, granting them full control over the Hub instance.
Business Impact
JetBrains Hub serves as a central authorization and user management point. A CVSS score of 9.1 reflects the critical risk; a successful exploit allows an attacker to modify user permissions, access sensitive integration tokens, and potentially pivot into other JetBrains tools like YouTrack or TeamCity, leading to a massive supply chain or data breach.
Remediation Plan
Immediate Action: Update JetBrains Hub to version 2025.3.119807 or later immediately.
Proactive Monitoring: Review administrative audit logs for any actions performed by unexpected IP addresses or during unusual timeframes.
Compensating Controls: Place the Hub instance behind a VPN or implement IP-based access control lists (ACLs) to restrict access to the administrative interface.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Feb 9, 2026, there is no public information indicating active exploitation. Because Hub manages identities for other critical development tools, this vulnerability is a high-value target for attackers.
Analyst Recommendation
Given that this is an unauthenticated authentication bypass, it must be treated with the highest urgency. Organizations should apply the update immediately to prevent unauthorized access to their identity management infrastructure.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
JetBrains TeamCity Relative Path Traversal Vulnerability - Active in CISA KEV catalog.
JetBrains TeamCity Relative Path Traversal Vulnerability - Active in CISA KEV catalog.
FEDERAL DEADLINE: May 3, 2026 (13 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. FEDERAL DEADLINE: May 3, 2026 (13 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Deadline: May 3, 2026
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
---METADATA---
VENDOR: JetBrains
PRODUCT: YouTrack
AFFECTED_VERSIONS: JetBrains YouTrack: 0 up to (excluding) 2026.2.17917
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
JetBrains YouTrack prior to version 2026.2.17917 contains a missing authorization vulnerability (CWE-862) that allows authenticated users to perform unauthorized actions.
Executive Summary:
A missing authorization vulnerability in JetBrains YouTrack allows authenticated attackers to gain unauthorized access to sensitive data and system functions.
Vulnerability Details
CVE-ID: CVE-2026-75051
Affected Software: JetBrains YouTrack
Affected Versions: JetBrains YouTrack: 0 up to (excluding) 2026.2.17917
Vulnerability: This vulnerability is a missing authorization flaw (CWE-862) where the application fails to properly verify user permissions. It requires the attacker to have low-level privileges (authenticated access) to exploit the flaw.
Business Impact
The ability for an authenticated user to bypass authorization checks can lead to significant data exposure or modification within the project management environment. With a CVSS score of 8.1, this is classified as a high-severity issue that could compromise the integrity and confidentiality of sensitive project tracking data.
Remediation Plan
Immediate Action: Update JetBrains YouTrack to version 2026.2.17917 or later to resolve the missing authorization flaw.
Proactive Monitoring: Review application access logs for unusual administrative actions or access to projects that fall outside of the assigned user role scope.
Compensating Controls: Ensure that internal network access to the YouTrack instance is restricted to authorized personnel only, limiting the pool of potential attackers.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of August 18, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The flaw is fundamentally an authorization logic error that requires an active user session to leverage.
Analyst Recommendation
Given the high CVSS score, organizations should prioritize patching this vulnerability to prevent potential privilege escalation or unauthorized data manipulation. Please verify the current version of your YouTrack installation and apply the update to the mandated version immediately.