CVE-2026-100253: JetBrains TeamCity

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL

Affected products

  • JetBrains TeamCity: before 2025.11.8 (fixed in 2025.11.8); from 2026.1, before 2026.1.4 (fixed in 2026.1.4)

Published 2026-09-30. Last modified 2026-10-06.