OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-106218

HIGH · CVSS 8.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

JetBrains TeamCity versions prior to 2026.1.3 and 2025.11.7 are vulnerable to a Kotlin DSL sandbox escape, which could allow an attacker to execute arbitrary code on the server. This high-severity vulnerability poses a significant risk to users managing CI/CD pipelines, as it could lead to unauthorized access and control over the server environment. Organizations utilizing TeamCity should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-106218
Severity
HIGH
CVSS
8.8
EPSS
0.27%

Original NVD Description

In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible

Related CVEs

Other vulnerabilities affecting the same vendor(s)