Description
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
Published: 2026-07-23
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains TeamCity versions before 2026.1.2 and 2025.11.6 contain a Kotlin DSL sandbox escape that permits an attacker to execute arbitrary Kotlin code. The vulnerability is a code injection flaw (CWE‑94), providing the attacker with full compromise of confidentiality, integrity, and availability for the affected system. By crafting a malicious DSL script, an attacker can run any code with the permissions of the TeamCity server process.

Affected Systems

The vulnerable products are JetBrains TeamCity, affected by versions earlier than 2026.1.2 and 2025.11.6. Any installation of these releases that accepts external Kotlin DSL scripts is susceptible.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity risk, while the EPSS score of less than 1% suggests that, as of now, exploitation incidence is low. The vulnerability is not yet listed in the CISA KEV catalog. The attack vector is presumably remote, as it can be triggered when an attacker can upload or modify a Kotlin DSL script in a project, thereby escaping the sandbox and executing arbitrary code on the TeamCity host.

Generated by OpenCVE AI on August 3, 2026 at 21:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains TeamCity to version 2026.1.2 or later, which incorporates the sandbox fix.
  • Restrict external Kotlin DSL script uploads so that only trusted administrators can create or modify scripts within TeamCity.
  • Monitor TeamCity logs for suspicious DSL script activity and configure alerts for unexpected script execution.

Generated by OpenCVE AI on August 3, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*

Mon, 03 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Kotlin DSL Sandbox Escape Allows Remote Code Execution in JetBrains TeamCity

Thu, 30 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Kotlin DSL Sandbox Escape Allows Remote Code Execution in JetBrains TeamCity

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains teamcity
Vendors & Products Jetbrains
Jetbrains teamcity

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Jetbrains Teamcity
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-24T03:56:18.917Z

Reserved: 2026-07-23T12:24:36.330Z

Link: CVE-2026-65906

cve-icon Vulnrichment

Updated: 2026-07-23T14:50:09.151Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-23T13:16:31.733

Modified: 2026-08-11T15:59:11.910

Link: CVE-2026-65906

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:45:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')