CVE-2026-49371: XSS
Published May 29, 2026
·Updated
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
Affected Software
2 affected components
JetBrains TeamCity<2026.1.1
JetBrains TeamCity<2026.1.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains TeamCityto a version that resolves this vulnerability.Fixed in 2026.1.1
Event History
May 29, 2026
CVE Published
via MITRE·06:15 PM
Data Sourced
via MITRE·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-49371?
CVE-2026-49371 has a severity rating of 8.2, which is considered high.
2
What type of vulnerability is CVE-2026-49371?
CVE-2026-49371 is a reflected cross-site scripting (XSS) vulnerability.
3
How can I mitigate the risk of CVE-2026-49371?
To mitigate CVE-2026-49371, ensure to update JetBrains TeamCity to version 2026.1.1 or later.
4
What software is affected by CVE-2026-49371?
CVE-2026-49371 affects JetBrains TeamCity before version 2026.1.1.
5
Is there an immediate fix for CVE-2026-49371?
The only immediate fix for CVE-2026-49371 is to upgrade to the patched version provided by JetBrains.