CVE-2025-68267: Medium severity JetBrains TeamCity vulnerability
Published Dec 16, 2025
·Updated
In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token
Affected Software
1 affected component
JetBrains TeamCity<2025.11.1
Event History
Dec 16, 2025
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-68267?
The severity of CVE-2025-68267 is classified as a high risk due to the potential for unauthorized access through excessive privileges.
2
How do I fix CVE-2025-68267?
To fix CVE-2025-68267, update JetBrains TeamCity to version 2025.11.1 or later.
3
What are the potential impacts of CVE-2025-68267?
CVE-2025-68267 can lead to unauthorized actions and exposure of sensitive data due to improper token storage.
4
Who is affected by CVE-2025-68267?
JetBrains TeamCity users running versions prior to 2025.11.1 are affected by CVE-2025-68267.
5
What was the root cause of CVE-2025-68267?
The root cause of CVE-2025-68267 was the use of a GitHub personal access token instead of a more secure installation token.