Sceawere

Vulnerability Detail

CVE-2026-106218UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TeamCity Kotlin DSL RCE Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
8h ago
Vendor
JetBrains
Product
TeamCity
Attack Type
CWE-184
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-06T17:17:24.433Z",
  "pubdate": "2026-10-06T17:17:24.433Z",
  "executiveSummary": "This vulnerability involves a sandbox escape within the Kotlin DSL processing engine of JetBrains TeamCity, allowing for Remote Code Execution (RCE) on the server.\nThe flaw stems from insufficient isolation within the Kotlin DSL execution environment, enabling an attacker to break out of the intended sandbox and execute arbitrary code with the privileges of the TeamCity server process.\nAffected products include JetBrains TeamCity versions prior to 2026.1.3 and 2025.11.7.\nThe risk profile is critical, as successful exploitation grants an attacker full control over the TeamCity server, potentially leading to unauthorized access to source code, build artifacts, sensitive credentials, and lateral movement within the build infrastructure.\nExploitation generally requires the ability to define or modify project configurations that utilize Kotlin DSL, which may be accessible to users with project-level administrative or configuration permissions.\nThe vulnerability represents a significant security breakdown in the product's isolation mechanism designed to protect the host environment from untrusted build configuration scripts.",
  "technicalDetails": "The root cause of this vulnerability is a sandbox escape flaw located in the Kotlin DSL execution environment of JetBrains TeamCity. TeamCity supports Kotlin DSL to define build configurations as code, which are compiled and executed on the server-side to generate build pipelines.\nUnder normal operating conditions, the Kotlin DSL execution is intended to be restricted to a limited set of APIs and classes, preventing scripts from interacting with the underlying server runtime, filesystem, or arbitrary system commands. However, the flaw allows an attacker to bypass these restrictions.\nThe attack flow initiates when an authenticated user—or an attacker with sufficient permissions to modify Kotlin DSL project configurations—submits a malicious DSL script. By leveraging reflection, specific library vulnerabilities within the sandbox dependencies, or inadequately protected internal API surfaces, the attacker can break out of the restricted JVM sandbox.\nUpon escaping the sandbox, the attacker executes arbitrary code within the TeamCity server's context. Because the TeamCity service typically runs with elevated privileges to orchestrate builds, the payload executes with the same permissions, facilitating full system compromise.\nThe vulnerable component is the Kotlin DSL parser and executor service. The issue affects JetBrains TeamCity versions prior to 2026.1.3 and 2025.11.7. This vulnerability does not inherently require network exposure beyond the TeamCity web interface, provided the attacker can manipulate DSL-based build configurations.\nPost-exploitation impact includes persistent server access, exfiltration of environment variables, access to stored secrets (e.g., deployment keys, API tokens), and the ability to inject malicious code into build processes, effectively facilitating a supply chain attack. The complexity of this exploitation relies on the ability to bypass the Java security manager or similar classloader-based isolation mechanisms implemented in the TeamCity environment."
}
CVE-2026-106218: TeamCity Kotlin DSL RCE Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere