CVE-2026-65906: Code Injection
Published Jul 23, 2026
·Updated
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
Affected Software
1 affected component
JetBrains TeamCity<2026.1.2
Event History
Jul 23, 2026
CVE Published
via MITRE·12:24 PM
Data Sourced
via MITRE·12:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65906?
The severity of CVE-2026-65906 is rated as high with a score of 8.8.
2
How do I fix CVE-2026-65906?
To fix CVE-2026-65906, update JetBrains TeamCity to version 2026.1.2 or later.
3
What types of systems are affected by CVE-2026-65906?
CVE-2026-65906 affects JetBrains TeamCity versions prior to 2026.1.2 and 2025.11.6.
4
What is the main vulnerability of CVE-2026-65906?
The main vulnerability of CVE-2026-65906 is code execution via a Kotlin DSL sandbox escape.
5
Can CVE-2026-65906 lead to data compromise?
Yes, CVE-2026-65906 allows for heightened access which can lead to data compromise.