CVE-2026-65907
A critical flaw in JetBrains TeamCity allows attackers to run arbitrary code on the server by manipulating Git VCS roots. The vulnerability exists in versions before 2026.1.2 and 2025.11.6. It can be fixed by upgrading to a newer release.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
JetBrains TeamCity, versions prior to 2026.1.2 and 2025.11.6, used by organizations that host CI/CD pipelines.
Real-world impact
An attacker could take full control of the TeamCity server, compromising all projects, data, and potentially the underlying infrastructure.
Why this severity
The CVSS score of 9.1 reflects that the flaw can be exploited over the network with low effort, requires high privileges, and can compromise confidentiality, integrity, and availability, making it a critical risk.
What to do about it
- 01Verify your TeamCity version.
- 02Download the latest TeamCity release (2026.1.2 or newer, or 2025.11.6 or newer).
- 03Install the update following the vendor’s instructions.
- 04Restart the TeamCity service.
NVD description
Timeline
- Jul 23, 2026 · 9d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 9d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.