Stored XSS Vulnerability in JetBrains TeamCity SAML Login Page
CVE-2026-49381

3.4LOW

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-49381?

A stored Cross-Site Scripting (XSS) vulnerability exists in the SAML login page of JetBrains TeamCity versions prior to 2026.1. This flaw allows attackers to inject malicious scripts into the application, potentially compromising user accounts and leading to unauthorized access. Proper input validation and sanitization measures are essential to mitigate the risks associated with this vulnerability.

Affected Version(s)

TeamCity 0 < 2026.1

References

CVSS V3.1

Score:
3.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.