In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Jetbrains Teamcity
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
|
— |
2025.11.7
|
|
Jetbrains Teamcity
cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
|
2026.1
|
2026.1.3
|