CVE-2026-59794: XSS
Published Jul 10, 2026
·Updated
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
Affected Software
2 affected components
JetBrains TeamCity<2026.1.2
JetBrains TeamCity<2026.1.2
Event History
Jul 10, 2026
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-59794?
The severity of CVE-2026-59794 is rated as high with a score of 7.3.
2
How do I fix CVE-2026-59794?
To fix CVE-2026-59794, upgrade JetBrains TeamCity to version 2026.1.2 or later.
3
What type of vulnerability is CVE-2026-59794?
CVE-2026-59794 is a stored cross-site scripting (XSS) vulnerability.
4
Where does CVE-2026-59794 occur in JetBrains TeamCity?
CVE-2026-59794 occurs on the cloud profile page through agent-reported data.
5
What impact does CVE-2026-59794 have on security?
CVE-2026-59794 allows attackers to execute arbitrary scripts in the context of a user's session, compromising data confidentiality and integrity.