Excessive Privileges Issue in JetBrains TeamCity by JetBrains
CVE-2025-68267

6.5MEDIUM

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
16 December 2025

What is CVE-2025-68267?

In JetBrains TeamCity prior to version 2025.11.1, a vulnerability allows for excessive privileges due to the improper storage of GitHub personal access tokens instead of using the more secure installation tokens. This mismanagement of access tokens could potentially lead to unauthorized access and manipulation of sensitive resources, highlighting the need for proper token management and access controls in software development environments.

Affected Version(s)

TeamCity 0 < 2025.11.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-68267 : Excessive Privileges Issue in JetBrains TeamCity by JetBrains