people · May 20, 2026
JetBrains Patches High-Severity TeamCity Vulnerability CVE-2026-44413 in 2026.1
Share the canonical public link.
JetBrains addressed high-severity post-authentication vulnerability CVE-2026-44413 in TeamCity On-Premises. The flaw affects versions through 2025.11.4 and allows authenticated users to expose parts of the TeamCity server REST API including API tokens, Git credentials, build secrets and logs to unauthorized parties. The fix appears in version 2026.1 with a security patch plugin available for versions 2017.1 and later. Researcher Martin Orem of Binary House privately reported the issue on April 30, 2026. TeamCity Cloud remains unaffected.