JetBrains TeamCity Guest Access Detected

medium Web App Scanning Plugin ID 115110

Synopsis

JetBrains TeamCity Guest Access Detected

Description

JetBrains TeamCity is a continuous integration and build management system that allows guest access if the feature is enabled. If guest login is enabled, an attacker can access the TeamCity server without authentication, potentially leading to unauthorized access to sensitive information and system functionalities.

Solution

If guest login is not required, disable the guest login feature in the TeamCity administration interface to prevent unauthorized access.

See Also

https://ph33r.medium.com/misconfig-in-teamcity-panel-lead-to-auth-bypass-in-apache-org-0day-146f6a1a4e2b

https://www.jetbrains.com/help/teamcity/guest-user.html

https://www.jetbrains.com/teamcity/

Plugin Details

Severity: Medium

ID: 115110

Type: remote

Published: 1/15/2026

Updated: 1/15/2026

Scan Template: basic, full, pci, scan

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: Tenable

CVSS v3

Risk Factor: High

Base Score: 7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information