Three new JetBrains software vulnerabilities expose developers to severe security risks. Attackers can execute arbitrary code on TeamCity servers and inject SQL queries into Exposed frameworks. Administrators must apply available patches immediately.
- Product: JetBrains (2 products)
- Vulnerabilities: 3 flaws (CVE-2026-108474, CVE-2026-106219, CVE-2026-106218)
- Highest severity: 9.8 (Critical Β· CVSSv3)
- Status: No confirmed exploitation yet; patches available
- Action: Update to 1.5.1, 2026.2.1, 2026.1.3 2025.11.7 now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-108474 | 9.8 | CWE-89 | 1.5.1 | Not exploited |
| CVE-2026-106218 | 8.8 | CWE-184 | 2026.1.3 2025.11.7 | Not exploited |
| CVE-2026-106219 | 6.5 | CWE-73 | 2026.2.1 | Not exploited |
Turn matching CVEs into GitHub Issues automatically β no copy-pasting, no duplicates.
Try Team free for 14 daysImpact on Development Environments
These JetBrains software vulnerabilities affect critical development infrastructure. TeamCity manages source code building and deployment. Therefore, a server compromise gives attackers deep access to proprietary codebases. Software supply chain security demands secure build systems. A compromised pipeline allows hackers to inject backdoors into production applications. Similarly, the Exposed framework handles database interactions. A breach here leaks sensitive database records. Security researchers have not confirmed any public exploitation or proof-of-concept activity. Furthermore, the vendor has not provided affected installation counts.
Attack Mechanisms
The most severe flaw impacts the Exposed framework. Specifically, the framework fails to escape string arguments in several SQL functions. Attackers use this oversight to inject malicious SQL commands. This flaw holds a critical severity rating. It requires no authentication to exploit.
Meanwhile, TeamCity suffers from two distinct issues. First, the application fails to validate Git submodule URLs. This flaw allows malicious actors to read local repositories stored on the server. Second, a sandbox escape exists within the Kotlin DSL integration. This bug enables attackers to execute arbitrary code directly on the TeamCity host.
Vulnerable Software Versions
The SQL injection bug affects JetBrains Exposed versions before 1.5.1. The Git submodule URL flaw impacts TeamCity versions prior to 2026.2.1. Finally, the Kotlin DSL sandbox escape affects TeamCity versions before 2026.1.3 and 2025.11.7.
Mitigation Steps
Administrators must update JetBrains Exposed to version 1.5.1. Furthermore, teams should upgrade TeamCity to version 2026.2.1 immediately. Users on older TeamCity branches must update to at least 2025.11.7 to fix the code execution flaw. Patching these systems prevents unauthorized access. Do not delay these critical updates. Security teams can review the official JetBrains security advisories for specific patch details.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!