CyberRota Analysis
AI-GeneratedJetBrains TeamCity versions prior to 2026.2, 2026.1.4, and 2025.11.8 are vulnerable to an administrator account takeover due to a flaw in the password reset functionality. This vulnerability allows an attacker to exploit the reset process to gain unauthorized access to admin accounts, potentially compromising the entire CI/CD environment. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and maintain the integrity of their development pipelines.
Original NVD Description
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
Related CVEs
Other vulnerabilities affecting the same vendor(s)