CVE-2026-106218
- EPSS 0.27%
- Veröffentlicht 06.10.2026 16:33:06
- Zuletzt bearbeitet 07.10.2026 04:17:52
In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
CVE-2026-106219
- EPSS 0.62%
- Veröffentlicht 06.10.2026 16:33:06
- Zuletzt bearbeitet 06.10.2026 20:03:40
In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server
CVE-2026-100255
- EPSS 0.34%
- Veröffentlicht 30.09.2026 15:17:46
- Zuletzt bearbeitet 02.10.2026 20:46:45
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
CVE-2026-100254
- EPSS 0.46%
- Veröffentlicht 30.09.2026 15:17:45
- Zuletzt bearbeitet 06.10.2026 16:42:11
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings
CVE-2026-100253
- EPSS 0.43%
- Veröffentlicht 30.09.2026 15:17:44
- Zuletzt bearbeitet 06.10.2026 16:40:33
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL
CVE-2026-63077
- EPSS 10.72%
- Veröffentlicht 27.07.2026 16:44:32
- Zuletzt bearbeitet 06.08.2026 05:17:05
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
CVE-2026-65907
- EPSS 0.42%
- Veröffentlicht 23.07.2026 12:28:40
- Zuletzt bearbeitet 24.07.2026 05:16:49
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
- EPSS 0.42%
- Veröffentlicht 23.07.2026 12:24:44
- Zuletzt bearbeitet 11.08.2026 15:59:11
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
CVE-2026-59795
- EPSS 0.26%
- Veröffentlicht 10.07.2026 14:18:59
- Zuletzt bearbeitet 13.07.2026 15:27:58
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
CVE-2026-59796
- EPSS 0.27%
- Veröffentlicht 10.07.2026 14:18:59
- Zuletzt bearbeitet 14.07.2026 05:16:19
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks