vulnerability

JetBrains TeamCity: CVE-2025-68267: Excessive privileges were possible due to storing GitHub personal access token instead of an installation token (TW-97528)

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
Dec 16, 2025
Added
Dec 17, 2025
Modified
Dec 17, 2025

Description

In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token

Solution

jetbrains-teamcity-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.