CVE-2026-106218: High severity JetBrains TeamCity vulnerability
Published Oct 6, 2026
·Updated
In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
Affected Software
1 affected component
JetBrains TeamCity<2026.1.3, <2025.11.7
Event History
Oct 6, 2026
CVE Published
via MITRE·04:33 PM
Data Sourced
via MITRE·04:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which TeamCity installations are affected?
JetBrains TeamCity versions before 2026.1.3 and 2025.11.7 are affected.
2
What access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges and can exploit the issue remotely without user interaction. Exploitation involves escaping the Kotlin DSL sandbox and can result in remote code execution on the TeamCity server.
3
What is the impact of successful exploitation?
Successful exploitation can provide remote code execution on the TeamCity server. The listed CVSS impacts indicate high confidentiality, integrity, and availability impact.