Junglewise Threat Intelligence

CVE-2026-65907: JetBrains TeamCity code execution in Git VCS roots

CVE-2026-65907 · Severity: critical · CVSS 9.1 · Published 2026-07-23

Technologies: Jetbrains TeamCity. Vendors: Jetbrains.

Executive brief

JetBrains TeamCity, a continuous integration and deployment server used to automate software building and testing, contains a vulnerability that could allow an attacker to execute malicious code. By exploiting the way the system handles Git repository connections, an attacker could gain full control over the build server. This could lead to the theft of source code, intellectual property, or the compromise of the entire software delivery pipeline.

Technical details

A code injection vulnerability (CWE-94) exists in JetBrains TeamCity's Git Version Control System (VCS) root configuration. The flaw allows an attacker with high-level administrative privileges to execute arbitrary code on the TeamCity server by manipulating Git VCS root settings. The vulnerability is reachable over the network without user interaction, though it requires 'High' privileges (PR:H). Successful exploitation results in a scope change (S:C), potentially allowing the attacker to move beyond the TeamCity application to the underlying host system. The issue is fixed in versions 2026.1.2 and 2025.11.6.

Affected products

  • JetBrains TeamCity before 2026.1.2, 2025.11.6

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats