← Back
CVE-2026-65907
critical
CVSS 9.1
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
Summary
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
AI summary snake-internal / snake-template-v1
A weakness called CVE-2026-65907 was discovered in In JetBrains TeamCity before.
In plain terms, it is a flaw where attacker-supplied code gets executed by the program.
Severity is Critical (CVSS 9.1/10). If exploited, attackers can fully take over the affected system.
What you should do: update the affected software to the latest version. If unsure, ask your IT team or search the vendor's site for "In JetBrains TeamCity before CVE-2026-65907".
CVE-2026-65907 (In JetBrains TeamCity before). Severity: Critical / CVSSv3 9.1. Category: CWE-94.
Response plan:
1. Check the vendor advisory for affected versions and the patched release.
2. If a vulnerable version is running in production, schedule maintenance (urgency from KEV/CVSS).
3. If no patch yet, mitigate via WAF rule, disabling the affected feature, etc.
4. Monitor logs / SIEM for known IOC and PoC signatures of this CVE.
PoCs and fix commits: see the 'References' section, MITRE, and NVD.
❓ What is the problem
A weakness (CVE-2026-65907) in In JetBrains TeamCity before. In plain words, it is a flaw where attacker-supplied code gets executed by the program.
📍 Affected scope
Target versions of In JetBrains TeamCity before (see vendor advisory). If running in production, identify exposure immediately.
🔥 Severity
Severity: Critical (CVSS 9.1/10). If exploited, attackers can fully take over the affected system.
🔧 How to fix
Update to the patched release as listed in the vendor advisory. (Typical mitigation pattern for CWE-94)
🛡️ Workaround
If a patch is not yet available, consider disabling the affected feature, applying WAF rules, blocking via network ACLs, or isolating the vulnerable version.
🔍 Detection
Check version information, scan dependencies via SBOM, and monitor SIEM for IOC and PoC signatures related to this CVE.