JetBrains TeamCity CVE-2026-106218 (CVSS 8.8): Kotlin DSL sandbox escape gives authenticated users code execution on the server; fixed in 2026.1.3 and 2025.11.7
JetBrains, as CVE numbering authority, published CVE-2026-106218 on 6 October 2026: in TeamCity before 2026.1.3 and 2025.11.7, the Kotlin DSL sandbox could be escaped, leading to remote code execution on the TeamCity server. JetBrains scores it 8.8 under CVSS 3.1, needing low privileges and no user interaction, so any user able to supply Kotlin DSL project settings should be treated as able to run code on the build server. JetBrains published a second TeamCity CVE the same day, CVE-2026-106219 (CVSS 6.5): before 2026.2.1, missing validation of Git submodule URLs let users read local repositories on the server. No exploitation has been reported. Earlier TeamCity flaws disclosed in 2023 and 2024 were exploited soon after release, so internet-reachable build servers should be patched quickly. Primary: JetBrains CVE records and fixed security issues page.
- Product
- JetBrains TeamCity (on-premises)
- Versions
- CVE-2026-106218: before 2026.1.3 and 2025.11.7. CVE-2026-106219: before 2026.2.1.
- CVSS
- High (CVE-2026-106218, CVSS 3.1); 6.5 Medium (CVE-2026-106219)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade on-premises TeamCity to 2026.2.1 or later, or at least to 2026.1.3 or 2025.11.7 for the sandbox escape. Until then, limit who can edit versioned settings or push Kotlin DSL to projects, keep the TeamCity server off the internet, and review recent changes to .teamcity settings directories in your repositories.
Primary: JetBrains — Fixed security issues (TeamCity CVE-2026-106218 and CVE-2026-106219) · Vendor: CVE record — CVE-2026-106218 (JetBrains CNA, 6 Oct 2026) · CVE: CVE-2026-106218, CVE-2026-106219
