CVE-2026-59795: XSS
Published Jul 10, 2026
·Updated
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
Affected Software
2 affected components
JetBrains TeamCity<2026.1.2
JetBrains TeamCity<2026.1.2
Event History
Jul 10, 2026
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-59795?
The severity of CVE-2026-59795 is high with a score of 8.1.
2
What type of vulnerability is CVE-2026-59795?
CVE-2026-59795 is a stored Cross-Site Scripting (XSS) vulnerability.
3
How do I fix CVE-2026-59795?
To fix CVE-2026-59795, update JetBrains TeamCity to version 2026.1.2 or later.
4
What could happen if CVE-2026-59795 is exploited?
If exploited, CVE-2026-59795 could allow attackers to execute malicious scripts in the context of an affected user's session.
5
Is authentication required to exploit CVE-2026-59795?
No, CVE-2026-59795 can be exploited without authentication through unauthenticated agent registration.