CVE-2026-106218(jetbrains / teamcity)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-184

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • teamcity

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
teamcity

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-08: 110-08
Full discourse1 post
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-106218 Vendor → Jetbrains Severity → Critical — CVSS 10.0 Product → Teamcity Date → 2026-10-06 A critical vulnerability (Incomplete List of Disallowed Inputs) has been disclosed affecting Teamcity. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Jetbrains

    0000065
    452 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjetbrainsteamcity---

Explore more