Jetbrains Vulnerabilities
Comprehensive security vulnerability database for Jetbrains products
5
0
3
0
Severity Distribution
| Description | Vendor / Product | Exploit Status | |||
|---|---|---|---|---|---|
| CVE-2026-28196 | 2.3 | This vulnerability allows an attacker with access to the TeamCity server to find and potentially misuse leftover credentials stored on the disk if versioned settings are disabled. It requires the attacker to have some level of access to the server where TeamCity is running. | jetbrainsteamcity | Theoretical | about 1 month agoFeb 25, 2026 |
| CVE-2026-28195 | 4.3 | This vulnerability allows an attacker to add unauthorized parameters to build configurations in JetBrains TeamCity, potentially leading to malicious code execution or data exposure. It occurs when project developers are not properly restricted, meaning anyone with access to the project can exploit this flaw. | jetbrainsteamcity | Exploit Available | about 1 month agoFeb 25, 2026 |
| CVE-2026-28194 | 6.1 | This vulnerability allows an attacker to redirect users to malicious websites during the project creation process in JetBrains TeamCity. It can be exploited if an attacker tricks a user into clicking a specially crafted link while using an affected version of the software. | jetbrainsteamcity | Exploit Available | about 1 month agoFeb 25, 2026 |
| CVE-2026-28193 | 5.3 | This vulnerability allows an attacker to send unauthorized requests to the app permissions endpoint in JetBrains YouTrack, potentially gaining access to sensitive information or altering permissions. To exploit this, the attacker needs to be able to interact with the application, meaning they must have some level of access to the YouTrack environment. | jetbrainsyoutrack | Theoretical | about 1 month agoFeb 25, 2026 |
| CVE-2020-29582 | 5.3 | An attacker can read sensitive data from temporary files and view directory contents created by JetBrains Kotlin versions before 1.4.21 due to weak security settings on those files. This vulnerability requires the attacker to have access to the system where the vulnerable version of Kotlin is running. | jetbrainskotlin | Exploit Available | about 5 years agoFeb 3, 2021 |
About Jetbrains Security
This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Jetbrains products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.
Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.