s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-49373

📛 CVE Title

JetBrains TeamCity: CVE-2026-49373: Remote code execution was possible via Perforce connection settings (TW-99632)

Description

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

Overview

State
Assigner (CNA)
CVSS severity
MEDIUM
CVSS score
CVSS 5.0 / 10 5.0 5.0 / 10
CVSS vector
AV:N/AC:L/Au:S/C:C/I:P/A:N
Effective score
5.0 / 10 MEDIUM source: CNA overview
CWE(s)
Reserved
Published
2026-05-29 00:00 UTC
Last updated
Source
https://www.rapid7.com/db/vulnerabilities/jetbrains-teamcity-cve-2026-49373/
Linked Threat
CVE-2026-49373 — CVE-2026-49373

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-05-29 19:16:27 UTC
NVD last modified
2026-07-22 06:10:00 UTC
NVD CVSS v3.1
CVSS 7.1 / 10 7.1 7.1 / 10 HIGH source: cve@jetbrains.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Exploitability subscore
2.8 / 10
Impact subscore
4.2 / 10
EPSS score
0.1303 (probability of exploitation in next 30 days)
EPSS percentile
95.94% vs all CVEs — higher = more likely to be exploited, as of 2026-07-28

NVD-assigned CWE(s): CWE-88 (differs from the CNA list above)

NVD / KEV / EPSS data refreshed 2026-07-28 16:22 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-33381
Assigner
JetBrains
Published
May 29, 2026, 6:15:48 PM
Updated
May 30, 2026, 3:57:37 AM
EUVD base score (CVSS 3.1)
7.1 / 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
EUVD-reported EPSS
13.0300
Vendors
JetBrains
Products
TeamCity (0 <2026.1)
Aliases
GHSA-hqxf-vmvp-qr3c

ENISA description: In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

EUVD references (1)

Affected products — CPE 2.3 (1) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*

Vendor references (0)

References embedded in the original CVE record by the assigning CNA.

None in the CVE record.

Web references (7)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (1)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (11)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-49373.json.

Not stored.