Description
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
Published: 2026-07-23
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In JetBrains TeamCity, versions prior to 2026.1.2 and 2025.11.6, a flaw permits arbitrary code execution through the handling of Git VCS roots. The vulnerability allows an attacker to run any command on the TeamCity server by influencing the processing of Git repositories, effectively compromising the entire host. This command injection weakness, identified as CWE‑94, can undermine confidentiality, integrity, and availability. The likely attack vector is that an attacker submits a malicious Git repository or manipulates the VCS root configuration accessed over the network, although the exact exploitation steps are not detailed in the advisory.

Affected Systems

JetBrains TeamCity servers running versions earlier than 2026.1.2 or 2025.11.6 are affected. Any installation that permits configuration of Git VCS roots falls under the scope of this vulnerability.

Risk and Exploitability

The CVSS score of 9.1 classifies the issue as critical, while the EPSS score of less than 1% indicates a very low observed exploitation probability at the time of analysis. The vulnerability is not yet listed in CISA's KEV catalog. Even with the low exploitation likelihood, the potential for remote code execution and the requirement for network access to the TeamCity administration interface or exposed Git endpoints make this a high‑risk scenario that warrants immediate attention.

Generated by OpenCVE AI on August 4, 2026 at 15:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TeamCity to version 2026.1.2 or later, which contains the fix for the command injection vulnerability in Git VCS roots.
  • If upgrading is not immediately possible, disable or remove any Git VCS roots that are not essential and block external access to Git repositories from the TeamCity instance.
  • Implement network‑level controls to restrict who can modify VCS root settings and monitor Git traffic for anomalous command activity that could indicate exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 15:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title TeamCity Git VCS Root Remote Code Execution Vulnerability

Sun, 02 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title TeamCity Git VCS Root Remote Code Execution Vulnerability

Thu, 30 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Code Execution via Git VCS Roots in JetBrains TeamCity

Mon, 27 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Code Execution via Git VCS Roots in JetBrains TeamCity

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains teamcity
Vendors & Products Jetbrains
Jetbrains teamcity
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Jetbrains Teamcity
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-24T03:56:19.827Z

Reserved: 2026-07-23T12:24:36.571Z

Link: CVE-2026-65907

cve-icon Vulnrichment

Updated: 2026-07-23T14:48:52.073Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-23T13:16:31.860

Modified: 2026-07-24T05:16:49.210

Link: CVE-2026-65907

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')