people · May 22, 2026
JetBrains Posts Security Patch for CVE-2026-44413 in TeamCity On-Premises
Share the canonical public link.
JetBrains identified and patched CVE-2026-44413, a high-severity post-authentication vulnerability in TeamCity On-Premises versions through 2025.11.4 that could allow authenticated users to expose parts of the server API to unauthorized access. The vulnerability was reported privately on April 30, 2026, by Martin Orem and assigned CVE-2026-44413; TeamCity Cloud was unaffected. JetBrains released version 2026.1 with the fix and a security patch plugin for versions 2017.1 and later, urging on-premises customers to upgrade or install the plugin. Help Net Security and NVD confirmed the privilege escalation details on May 12, 2026.