CVE-2026-106219: JetBrains TeamCity

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server

Affected products

  • JetBrains TeamCity: before 2026.2.1 (fixed in 2026.2.1)

Published 2026-10-06. Last modified 2026-10-08.