2025.11.5 authenticated users could expose server API to unauthorised access
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ |
|
Tue, 12 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:* |
Mon, 11 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Users May Expose TeamCity Server API to Unauthorized Access | |
| First Time appeared |
Jetbrains
Jetbrains teamcity |
|
| Vendors & Products |
Jetbrains
Jetbrains teamcity |
Mon, 11 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: JetBrains
Published:
Updated: 2026-05-11T18:35:23.104Z
Reserved: 2026-05-06T10:13:50.755Z
Link: CVE-2026-44413
No data.
Status : Analyzed
Published: 2026-05-11T18:16:38.053
Modified: 2026-05-12T19:59:34.543
Link: CVE-2026-44413
No data.
OpenCVE Enrichment
Updated: 2026-05-11T19:45:08Z