CVE-2026-28195

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to add unauthorized parameters to build configurations in JetBrains TeamCity, potentially leading to malicious code execution or data exposure. It occurs when project developers are not properly restricted, meaning anyone with access to the project can exploit this flaw.

Technical Description

In JetBrains TeamCity before 2025.11.3 missing authorization allowed project developers to add parameters to build configurations

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactNone
Integrity ImpactLow
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References