OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-100255

HIGH · CVSS 8.1 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

JetBrains TeamCity versions prior to 2026.2, 2026.1.4, and 2025.11.8 are vulnerable to an administrator account takeover due to a flaw in the password reset functionality. This vulnerability allows an attacker to exploit the reset process to gain unauthorized access to admin accounts, potentially compromising the entire CI/CD environment. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and maintain the integrity of their development pipelines.

CVE
CVE-2026-100255
Severity
HIGH
CVSS
8.1
EPSS
0.35%

Original NVD Description

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset

Related CVEs

Other vulnerabilities affecting the same vendor(s)