CVE-2026-100255: High severity JetBrains TeamCity vulnerability
Published Sep 30, 2026
·Updated
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
Affected Software
1 affected component
JetBrains TeamCity<2026.2, <2026.1.4, <2025.11.8
Event History
Sep 30, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which TeamCity versions need to be remediated?
TeamCity versions before 2026.2, 2026.1.4, and 2025.11.8 are affected. Upgrade to the applicable fixed release for your version line.
2
Does exploitation require an existing TeamCity account or user interaction?
No. The reported attack vector is network-based and requires no privileges or user interaction.
3
What is the potential impact of successful exploitation?
An attacker could take over an administrator account through the password-reset process. The reported impact includes high confidentiality, integrity, and availability consequences.