CVE-2026-106219: Medium severity JetBrains TeamCity vulnerability
Published Oct 6, 2026
·Updated
In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server
Affected Software
1 affected component
JetBrains TeamCity<2026.2.1
Event History
Oct 6, 2026
CVE Published
via MITRE·04:33 PM
Data Sourced
via MITRE·04:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is remotely reachable and has low attack complexity, but requires low-privileged access. It does not require user interaction.
2
What is the expected security impact?
The reported impact is high confidentiality impact: an attacker may read local repositories on the TeamCity server. No integrity or availability impact is indicated.
3
Which TeamCity installations need remediation?
JetBrains TeamCity versions before 2026.2.1 are affected. Updating to 2026.2.1 or later addresses the affected version range.