CVE-2026-65907: Code Injection
Published Jul 23, 2026
·Updated
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
Affected Software
1 affected component
JetBrains TeamCity<2026.1.2
Event History
Jul 23, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65907?
The severity of CVE-2026-65907 is rated as critical with a CVSS score of 9.1.
2
How do I fix CVE-2026-65907?
To fix CVE-2026-65907, update JetBrains TeamCity to version 2026.1.2 or later, or 2025.11.6.
3
What kind of vulnerability is CVE-2026-65907?
CVE-2026-65907 is a code injection vulnerability that allows code execution in Git VCS roots.
4
What versions of JetBrains TeamCity are affected by CVE-2026-65907?
CVE-2026-65907 affects JetBrains TeamCity versions prior to 2026.1.2 and 2025.11.6.
5
What can an attacker achieve by exploiting CVE-2026-65907?
An attacker exploiting CVE-2026-65907 can execute arbitrary code, which may compromise the system's integrity and confidentiality.