CVE-2026-44413Patch(jetbrains / teamcity)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jetbrains teamcity systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • teamcity

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 4 mentions (2026-05-12); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
teamcity

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-05-11: 1Mentions · 2026-05-12: 4Mentions · 2026-05-13: 1Mentions · 2026-06-23: 1Patch / Workaround · 2026-05-12: 3Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 4Technical Details · 2026-05-13: 1Technical Details · 2026-06-23: 105-1105-1205-1306-23
Signal classification2 categories
Patch
457.1%
Disclosure
342.9%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-111
Disclosure1
2026-05-124
Disclosure1Patch3
2026-05-131
Patch1
2026-06-231
Disclosure1
Full discourse7 posts
  • JetBrains TeamCity@teamcity
    Patch

    🚨 High-severity security issue affecting TeamCity On-Premises We’ve identified a high-severity post-authentication vulnerability (CVE-2026-44413) affecting all TeamCity On-Premises versions. TeamCity Cloud is NOT affected. We strongly recommend upgrading to TeamCity 2026.1 or installing the security patch plugin for 2017.1+ immediately. More details on our blog: https://jb.gg/avpjq1

    Post summary

    A high‑severity, post‑authentication vulnerability (CVE‑2026‑44413) affects all TeamCity On‑Premises releases; users are urged to upgrade to 2026.1 or apply the 2017.1+ security patch plugin immediately.

    02031537
    9.2K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High Missing Authentication for critical function in #JetBrains #TeamCity CVE-2026-44413 CVSS: 8.2 threat actors with prior authentication can gain unauthorized access to the server API, which can allow them to modify system configurations #Patch #Patch #Patch

    Post summary

    The post warns of CVE-2026-44413, a high‑severity missing‑authentication flaw in JetBrains TeamCity that could let attackers modify server configurations, and urges users to apply the patch.

    01001328
    7.2K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE-2026-44413: TeamCity Privilege Escalation Exposes API to Unauthenticated Access

    Post summary

    The post announces CVE-2026-44413, a privilege escalation issue that permits unauthenticated API access in TeamCity.

    1000046
    295 followersView on X
  • Cyber Netsec IO@NetSecIO
    Patch

    PATCH NOW: A high-severity vulnerability (CVE-2026-44413) in JetBrains TeamCity On-Premises allows any authenticated user to expose server APIs. All versions up to 2025.11.4 are affected. Upgrade to 2026.1 immediately. 💻🔧 #TeamCity #JetBrains #CI/CD https://t.co/em5TykwxfZ

    Post summary

    JetBrains TeamCity On‑Premises users are urged to patch to version 2026.1 due to a high‑severity vulnerability that permits authenticated users to expose server APIs.

    0000072
    53 followersView on X
  • Help Net Security@helpnetsecurity
    Disclosure

    JetBrains TeamCity vulnerability allows privilege escalation, API exposure (CVE-2026-44413) - https://www.helpnetsecurity.com/2026/05/12/jetbrains-teamcity-vulnerability-cve-2026-44413/ - @jetbrains #ContinuousIntegration #SoftwareDelivery #Vulnerability #Cybersecurity #CybersecurityNews https://t.co/ITlN56jCpv

    Post summary

    JetBrains TeamCity CVE-2026-44413 enables privilege escalation through exposed APIs, as announced in a news article.

    00000293
    60.1K followersView on X
  • Shah Sheikh@shah_sheikh
    Patch

    JetBrains TeamCity vulnerability allows privilege escalation, API exposure (CVE-2026-44413): JetBrains has patched a high-severity vulnerability (CVE-2026-44413) in TeamCity, its popular continuous integration and continuous delivery platform, and is… https://www.helpnetsecurity.com/2026/05/12/jetbrains-teamcity-vulnerability-cve-2026-44413/?utm_source=dlvr.it&utm_medium=twitter https://t.co/Xm2bQEOZa5

    Post summary

    JetBrains has released a patch for CVE-2026-44413, a high‑severity issue involving privilege escalation via API exposure; no PoC, exploit code, or active exploitation is reported.

    0000077
    2.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44413 In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access https://www.cve.org/CVERecord?id=CVE-2026-44413

    Post summary

    JetBrains TeamCity versions before 2026.1 allow authenticated users to expose the server API to unauthorized access, as documented in CVE-2026-44413.

    00000138
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjetbrainsteamcity---

Explore more