OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-100254

HIGH · CVSS 8.8 EPSS 0.47%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Authenticated users of JetBrains TeamCity versions prior to 2026.2, 2026.1.4, and 2025.11.8 are vulnerable to CRLF injection, allowing them to execute arbitrary commands on Windows servers. This high-severity vulnerability poses a significant risk to the integrity and security of affected systems. Organizations using these versions should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-100254
Severity
HIGH
CVSS
8.8
EPSS
0.47%
Windows

Original NVD Description

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings

Related CVEs

Other vulnerabilities affecting the same vendor(s)