Impact
A sandbox escape in JetBrains TeamCity allows an attacker to execute arbitrary code on the server. The flaw is triggered when a Kotlin DSL script is processed in an unsafe manner, leading to a remote code execution that compromises the confidentiality, integrity, and availability of the TeamCity instance.
Affected Systems
JetBrains TeamCity versions prior to 2026.1.3 and 2025.11.7 are vulnerable. Systems running these releases need to be considered potentially exposed.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. No EPSS data is available, and it is not listed in the CISA KEV catalog, so the current exploitation likelihood is unknown. The likely attack vector is a remote attack leveraging an untrusted Kotlin DSL script. Until a patch is applied, users remain at high risk.
OpenCVE Enrichment