Impact
JetBrains TeamCity versions prior to 2026.1.2 contain a flaw in the Perforce VCS integration that permits arbitrary file access, enabling the reading of any file located on the TeamCity server. This weakness is identified as CWE‑73.
Affected Systems
The affected product is JetBrains TeamCity, versions older than 2026.1.2. Users running TeamCity prior to the 2026.1.2 release are at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies this issue as high severity. The EPSS score indicates a very low exploitation probability (less than 1 percent), and the vulnerability is not listed in the CISA KEV catalog. The description does not specify a precise attack path, so the likely attack vector is inferred to involve the Perforce integration interfaces.
OpenCVE Enrichment