Description
In JetBrains TeamCity before 2026.1.3
2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
Published: 2026-10-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A sandbox escape in JetBrains TeamCity allows an attacker to execute arbitrary code on the server. The flaw is triggered when a Kotlin DSL script is processed in an unsafe manner, leading to a remote code execution that compromises the confidentiality, integrity, and availability of the TeamCity instance.

Affected Systems

JetBrains TeamCity versions prior to 2026.1.3 and 2025.11.7 are vulnerable. Systems running these releases need to be considered potentially exposed.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating high severity. No EPSS data is available, and it is not listed in the CISA KEV catalog, so the current exploitation likelihood is unknown. The likely attack vector is a remote attack leveraging an untrusted Kotlin DSL script. Until a patch is applied, users remain at high risk.

Generated by OpenCVE AI on October 6, 2026 at 17:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade JetBrains TeamCity to version 2026.1.3 or later, which contains the fix for the Kotlin DSL sandbox escape.
  • If an upgrade cannot be performed immediately, disable Kotlin DSL support or restrict DSL configuration access to trusted administrators only.
  • Review existing Kotlin DSL projects for untrusted code and remove or refactor them until the vulnerability is fixed.
  • Monitor TeamCity logs for unexpected script execution activity and investigate any anomalies promptly.

Generated by OpenCVE AI on October 6, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
Title Kotlin DSL Sandbox Escape Allows Remote Code Execution in JetBrains TeamCity

Tue, 06 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Description In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
Weaknesses CWE-184
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-10-06T17:00:23.392Z

Reserved: 2026-10-06T16:32:01.392Z

Link: CVE-2026-106218

cve-icon Vulnrichment

Updated: 2026-10-06T17:00:20.814Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T17:17:24.433

Modified: 2026-10-06T20:03:40.690

Link: CVE-2026-106218

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:00:05Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs