PatchSiren cyber security CVE debrief
CVE-2026-49380 JetBrains CVE debrief
A low-severity open redirect vulnerability exists in JetBrains TeamCity's SAML authentication plugin prior to version 2026.1. The flaw, classified as CWE-601 (URL Redirection to Untrusted Site), could allow an attacker to redirect users to malicious websites after authentication. The vulnerability requires network access and user interaction, with high attack complexity due to the need to bypass security mechanisms. No confidentiality impact or availability impact is associated with this issue; the integrity impact is rated low. The vulnerability was disclosed by JetBrains through their security issues page on May 29, 2026.
- Vendor
- JetBrains
- Product
- TeamCity
- CVSS
- LOW 3.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-29
- Original CVE updated
- 2026-05-29
- Advisory published
- 2026-05-29
- Advisory updated
- 2026-05-29
Who should care
Organizations running JetBrains TeamCity with SAML authentication enabled, particularly those using the built-in SAML plugin for single sign-on. Security teams responsible for CI/CD infrastructure and identity federation configurations should prioritize this patch to prevent potential phishing vectors through authentication redirects.
Technical summary
The SAML plugin in JetBrains TeamCity versions prior to 2026.1 contains an open redirect vulnerability (CWE-601). The flaw allows URL redirection to untrusted sites during the SAML authentication flow. The vulnerability is network-exploitable but requires high attack complexity and user interaction, resulting in a low CVSS 3.1 score of 3.1. Successful exploitation could enable phishing attacks by redirecting authenticated users to attacker-controlled destinations. No confidentiality or availability impact is associated with this vulnerability; integrity impact is low.
Defensive priority
low
Recommended defensive actions
- Upgrade JetBrains TeamCity to version 2026.1 or later to remediate the open redirect vulnerability in the SAML plugin.
- Review SAML authentication flows for unexpected redirect destinations if immediate patching is not feasible.
- Monitor authentication logs for anomalous redirect patterns that may indicate exploitation attempts.
- Validate that all SAML redirect URLs are explicitly allowlisted to prevent redirection to untrusted domains.
Evidence notes
CVE published 2026-05-29T19:16:27.990Z; modified 2026-05-29T20:11:15.977Z. CVSS 3.1 score 3.1 (LOW). Vector: AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N. CWE-601 identified. Vendor disclosure via JetBrains security issues page. NVD status: Undergoing Analysis.
Official resources
-
CVE-2026-49380 CVE record
CVE.org
-
CVE-2026-49380 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-05-29