CVE-2026-100253: High severity JetBrains TeamCity vulnerability
Published Sep 30, 2026
·Updated
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL
Affected Software
1 affected component
JetBrains TeamCity<2026.2, <2026.1.4, <2025.11.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JetBrains TeamCityto a version that resolves this vulnerability.Fixed in 2026.2
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which TeamCity installations are affected?
TeamCity versions before 2026.2, 2026.1.4, and 2025.11.8 are affected.
2
What access does an attacker need to exploit this issue?
The vulnerability has low privileges required and does not require user interaction. Exploitation is possible through the versioned settings Kotlin DSL.
3
What is the impact of successful exploitation?
A successful sandbox escape can lead to code execution with high confidentiality, integrity, and availability impact.