CVE-2026-49380
Open Redirect in JetBrains TeamCity SAML Plugin
Publication date: 2026-05-29
Last updated on: 2026-05-29
Assigner: JetBrains s.r.o.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| jetbrains | teamcity | to 2026.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-601 | The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an open redirect issue found in the SAML plugin of JetBrains TeamCity versions before 2026.1. An open redirect occurs when an application allows redirection to an untrusted URL, which can be exploited by attackers to redirect users to malicious sites.
How can this vulnerability impact me? :
The impact of this vulnerability is limited to the potential for attackers to redirect users to malicious websites through the open redirect in the SAML plugin. According to the CVSS score of 3.1, the vulnerability has low severity with no impact on confidentiality or availability, but it can cause limited integrity issues.