Thread Names Assigner Exposes Credentials in JetBrains TeamCity <2026.1
CVE-2026-49379 Published on May 29, 2026
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
Vulnerability Analysis
CVE-2026-49379 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Products Associated with CVE-2026-49379
Want to know whenever a new CVE is published for JetBrains Teamcity? stack.watch will email you.
Affected Versions
JetBrains TeamCity:- Before 2026.1 is affected.