PatchSiren cyber security CVE debrief
CVE-2026-65906 JetBrains CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T13:16:31.733Z and has not been modified since then. This vulnerability affects JetBrains TeamCity versions before 2026.1.2 or 2025.11.6, allowing for code execution via Kotlin DSL sandbox escape. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. Administrators and users should be aware of this vulnerability and take necessary actions to mitigate it.
- Vendor
- JetBrains
- Product
- TeamCity
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-23
- Original CVE updated
- 2026-08-11
- Advisory published
- 2026-07-23
- Advisory updated
- 2026-08-11
Who should care
Administrators and users of JetBrains TeamCity, especially those with versions before 2026.1.2 or 2025.11.6, should be aware of this vulnerability and take necessary actions to mitigate it. This includes verifying affected deployments, applying vendor-provided patches or updates, and monitoring TeamCity systems for suspicious activity.
Technical summary
A vulnerability in JetBrains TeamCity before 2026.1.2 and 2025.11.6 allows for code execution via Kotlin DSL sandbox escape. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. This issue affects administrators and users of JetBrains TeamCity, especially those with versions before 2026.1.2 or 2025.11.6.
Defensive priority
High priority due to the HIGH CVSS score of 8.8 and the possibility of code execution via Kotlin DSL sandbox escape.
Recommended defensive actions
- Inventory and verify TeamCity versions, checking for versions before 2026.1.2 or 2025.11.6
- Apply vendor-provided patches or updates to mitigate the vulnerability
- Monitor TeamCity systems for suspicious activity
- Implement compensating controls, such as network segmentation or access restrictions
- Review and update incident response plans to address potential code execution attacks
Evidence notes
Evidence from official sources indicates a vulnerability in JetBrains TeamCity before 2026.1.2 and 2025.11.6, allowing for code execution via Kotlin DSL sandbox escape. Limited details are available on the exact scope of affected systems and potential attack vectors. The CVE record was published on 2026-07-23T13:16:31.733Z and has not been modified since then. Further verification is recommended to confirm affected deployments and assess potential impact.
Official resources
-
CVE-2026-65906 CVE record
CVE.org
-
CVE-2026-65906 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T13:16:31.733Z and has not been modified since then.