people · May 20, 2026
Help Net Security Reports JetBrains TeamCity CVE-2026-44413 Privilege Escalation Patch
Share the canonical public link.
Help Net Security covered the JetBrains TeamCity CVE-2026-44413 vulnerability on May 12, 2026. The issue permits privilege escalation and exposure of TeamCity server API endpoints such as API tokens, Git credentials, build secrets, logs, usernames, emails, and roles, potentially allowing compromise of pipelines or repositories. It affects all TeamCity On-Premises installations up to and including version 2025.11.4. JetBrains recommends upgrading to 2026.1 or applying the security patch plugin for 2017.1+, and restricting inbound access to non-standard ports. The vulnerability was reported privately by Martin Orem.