In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
cve CVE-2026-100255 2 sources, 2 claims · Watch
NVD writes:
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset the claim
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset the claim
- Severity they disagree
- high GitHub advisoriesCRITICAL NVD
- CVSS they disagree
- 8.1 GitHub advisories9.8 NVD
- Vendor
- JetBrains NVD
- Product
- TeamCity NVD
- CWE
- CWE-1289 GitHub advisoriesCWE-1289 NVD
How far exploitation has got
- No public code known
- Proof of concept
- Proof of concept, verified
- A Metasploit module
- Exploited in the wild
- Used in ransomware campaigns
Timeline
| 2026-09-30 | first spoke of it: In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was... | GitHub advisories |
| 2026-09-30 | first spoke of it: In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset | NVD |
What it is to other things
| affects | jetbrains/teamcity NVD |
| made_by | jetbrains NVD |
Every value, with what each source said and its receipt
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Automatable automatable | NVD | no At least one of those steps needs a person. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "TeamCity",
"vendor": "JetBrains",
"versions": [
{
"lessThan": "2026.2, \n2026.1.4, \n2025.11.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "cve@jetbrains.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90B7BA91-8570-4A95-9C06-ABC6182E00A8",
"versionEndExcluding": "2025.11.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E68D7A2A-EDCD-4BEF-B205-F6000B6A9AA9",
"versionEndExcluding": "2026.1.4",
"versionStartIncluding": "2026.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset"
}
],
"id": "CVE-2026-100255",
"lastModified": "2026-10-02T20:46:45.227",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9,
"source": "cve@jetbrains.com",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-100255",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-30T16:16:56.100",
"references": [
{
"source": "cve@jetbrains.com",
"tags": [
"Vendor Advisory"
],
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"sourceIdentifier": "cve@jetbrains.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1289"
}
],
"source": "cve@jetbrains.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss conflict | GitHub advisories | 8.1receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-100255",
"cvss": {
"score": 8.1,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 8.1,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-1289",
"name": "Improper Validation of Unsafe Equivalence in Input"
}
],
"description": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset",
"epss": {
"percentage": 0.00431,
"percentile": 0.35004
},
"ghsa_id": "GHSA-4858-hf6j-x5pg",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-4858-hf6j-x5pg",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-4858-hf6j-x5pg"
},
{
"type": "CVE",
"value": "CVE-2026-100255"
}
],
"nvd_published_at": "2026-09-30T16:16:56Z",
"published_at": "2026-09-30T18:33:30Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-100255",
"https://www.jetbrains.com/privacy-security/issues-fixed",
"https://github.com/advisories/GHSA-4858-hf6j-x5pg"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was...",
"type": "unreviewed",
"updated_at": "2026-09-30T18:33:39Z",
"url": "https://api.github.com/advisories/GHSA-4858-hf6j-x5pg",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| CVSS cvss conflict | NVD | 9.8receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "TeamCity",
"vendor": "JetBrains",
"versions": [
{
"lessThan": "2026.2, \n2026.1.4, \n2025.11.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "cve@jetbrains.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90B7BA91-8570-4A95-9C06-ABC6182E00A8",
"versionEndExcluding": "2025.11.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E68D7A2A-EDCD-4BEF-B205-F6000B6A9AA9",
"versionEndExcluding": "2026.1.4",
"versionStartIncluding": "2026.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset"
}
],
"id": "CVE-2026-100255",
"lastModified": "2026-10-02T20:46:45.227",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9,
"source": "cve@jetbrains.com",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-100255",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-30T16:16:56.100",
"references": [
{
"source": "cve@jetbrains.com",
"tags": [
"Vendor Advisory"
],
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"sourceIdentifier": "cve@jetbrains.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1289"
}
],
"source": "cve@jetbrains.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS vector cvss_vector | NVD | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:Hreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "TeamCity",
"vendor": "JetBrains",
"versions": [
{
"lessThan": "2026.2, \n2026.1.4, \n2025.11.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "cve@jetbrains.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90B7BA91-8570-4A95-9C06-ABC6182E00A8",
"versionEndExcluding": "2025.11.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E68D7A2A-EDCD-4BEF-B205-F6000B6A9AA9",
"versionEndExcluding": "2026.1.4",
"versionStartIncluding": "2026.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset"
}
],
"id": "CVE-2026-100255",
"lastModified": "2026-10-02T20:46:45.227",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9,
"source": "cve@jetbrains.com",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-100255",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-30T16:16:56.100",
"references": [
{
"source": "cve@jetbrains.com",
"tags": [
"Vendor Advisory"
],
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"sourceIdentifier": "cve@jetbrains.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1289"
}
],
"source": "cve@jetbrains.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CWE cwe | GitHub advisories | CWE-1289receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-100255",
"cvss": {
"score": 8.1,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 8.1,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-1289",
"name": "Improper Validation of Unsafe Equivalence in Input"
}
],
"description": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset",
"epss": {
"percentage": 0.00431,
"percentile": 0.35004
},
"ghsa_id": "GHSA-4858-hf6j-x5pg",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-4858-hf6j-x5pg",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-4858-hf6j-x5pg"
},
{
"type": "CVE",
"value": "CVE-2026-100255"
}
],
"nvd_published_at": "2026-09-30T16:16:56Z",
"published_at": "2026-09-30T18:33:30Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-100255",
"https://www.jetbrains.com/privacy-security/issues-fixed",
"https://github.com/advisories/GHSA-4858-hf6j-x5pg"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was...",
"type": "unreviewed",
"updated_at": "2026-09-30T18:33:39Z",
"url": "https://api.github.com/advisories/GHSA-4858-hf6j-x5pg",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| CWE cwe | NVD | CWE-1289receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "TeamCity",
"vendor": "JetBrains",
"versions": [
{
"lessThan": "2026.2, \n2026.1.4, \n2025.11.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "cve@jetbrains.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90B7BA91-8570-4A95-9C06-ABC6182E00A8",
"versionEndExcluding": "2025.11.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E68D7A2A-EDCD-4BEF-B205-F6000B6A9AA9",
"versionEndExcluding": "2026.1.4",
"versionStartIncluding": "2026.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset"
}
],
"id": "CVE-2026-100255",
"lastModified": "2026-10-02T20:46:45.227",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9,
"source": "cve@jetbrains.com",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-100255",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-30T16:16:56.100",
"references": [
{
"source": "cve@jetbrains.com",
"tags": [
"Vendor Advisory"
],
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"sourceIdentifier": "cve@jetbrains.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1289"
}
],
"source": "cve@jetbrains.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Exploitation exploitation | NVD | none No evidence of exploitation, and no public proof of concept. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "TeamCity",
"vendor": "JetBrains",
"versions": [
{
"lessThan": "2026.2, \n2026.1.4, \n2025.11.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "cve@jetbrains.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90B7BA91-8570-4A95-9C06-ABC6182E00A8",
"versionEndExcluding": "2025.11.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E68D7A2A-EDCD-4BEF-B205-F6000B6A9AA9",
"versionEndExcluding": "2026.1.4",
"versionStartIncluding": "2026.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset"
}
],
"id": "CVE-2026-100255",
"lastModified": "2026-10-02T20:46:45.227",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9,
"source": "cve@jetbrains.com",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-100255",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-30T16:16:56.100",
"references": [
{
"source": "cve@jetbrains.com",
"tags": [
"Vendor Advisory"
],
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"sourceIdentifier": "cve@jetbrains.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1289"
}
],
"source": "cve@jetbrains.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Product product | NVD | TeamCityreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "TeamCity",
"vendor": "JetBrains",
"versions": [
{
"lessThan": "2026.2, \n2026.1.4, \n2025.11.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "cve@jetbrains.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90B7BA91-8570-4A95-9C06-ABC6182E00A8",
"versionEndExcluding": "2025.11.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E68D7A2A-EDCD-4BEF-B205-F6000B6A9AA9",
"versionEndExcluding": "2026.1.4",
"versionStartIncluding": "2026.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset"
}
],
"id": "CVE-2026-100255",
"lastModified": "2026-10-02T20:46:45.227",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9,
"source": "cve@jetbrains.com",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-100255",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-30T16:16:56.100",
"references": [
{
"source": "cve@jetbrains.com",
"tags": [
"Vendor Advisory"
],
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"sourceIdentifier": "cve@jetbrains.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1289"
}
],
"source": "cve@jetbrains.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity conflict | GitHub advisories | high From 7.0 to 8.9. receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-100255",
"cvss": {
"score": 8.1,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 8.1,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-1289",
"name": "Improper Validation of Unsafe Equivalence in Input"
}
],
"description": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset",
"epss": {
"percentage": 0.00431,
"percentile": 0.35004
},
"ghsa_id": "GHSA-4858-hf6j-x5pg",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-4858-hf6j-x5pg",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-4858-hf6j-x5pg"
},
{
"type": "CVE",
"value": "CVE-2026-100255"
}
],
"nvd_published_at": "2026-09-30T16:16:56Z",
"published_at": "2026-09-30T18:33:30Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-100255",
"https://www.jetbrains.com/privacy-security/issues-fixed",
"https://github.com/advisories/GHSA-4858-hf6j-x5pg"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was...",
"type": "unreviewed",
"updated_at": "2026-09-30T18:33:39Z",
"url": "https://api.github.com/advisories/GHSA-4858-hf6j-x5pg",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| Severity severity conflict | NVD | CRITICAL From the CVSS base score at 9.0 and above. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "TeamCity",
"vendor": "JetBrains",
"versions": [
{
"lessThan": "2026.2, \n2026.1.4, \n2025.11.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "cve@jetbrains.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90B7BA91-8570-4A95-9C06-ABC6182E00A8",
"versionEndExcluding": "2025.11.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E68D7A2A-EDCD-4BEF-B205-F6000B6A9AA9",
"versionEndExcluding": "2026.1.4",
"versionStartIncluding": "2026.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset"
}
],
"id": "CVE-2026-100255",
"lastModified": "2026-10-02T20:46:45.227",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9,
"source": "cve@jetbrains.com",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-100255",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-30T16:16:56.100",
"references": [
{
"source": "cve@jetbrains.com",
"tags": [
"Vendor Advisory"
],
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"sourceIdentifier": "cve@jetbrains.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1289"
}
],
"source": "cve@jetbrains.com",
"type": "Secondary"
}
]
}
} | critical | ||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "TeamCity",
"vendor": "JetBrains",
"versions": [
{
"lessThan": "2026.2, \n2026.1.4, \n2025.11.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "cve@jetbrains.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90B7BA91-8570-4A95-9C06-ABC6182E00A8",
"versionEndExcluding": "2025.11.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E68D7A2A-EDCD-4BEF-B205-F6000B6A9AA9",
"versionEndExcluding": "2026.1.4",
"versionStartIncluding": "2026.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset"
}
],
"id": "CVE-2026-100255",
"lastModified": "2026-10-02T20:46:45.227",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9,
"source": "cve@jetbrains.com",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-100255",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-30T16:16:56.100",
"references": [
{
"source": "cve@jetbrains.com",
"tags": [
"Vendor Advisory"
],
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"sourceIdentifier": "cve@jetbrains.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1289"
}
],
"source": "cve@jetbrains.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Technical impact technical_impact | NVD | total The attacker gains full control of the component, or all of its information. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "TeamCity",
"vendor": "JetBrains",
"versions": [
{
"lessThan": "2026.2, \n2026.1.4, \n2025.11.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "cve@jetbrains.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90B7BA91-8570-4A95-9C06-ABC6182E00A8",
"versionEndExcluding": "2025.11.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E68D7A2A-EDCD-4BEF-B205-F6000B6A9AA9",
"versionEndExcluding": "2026.1.4",
"versionStartIncluding": "2026.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset"
}
],
"id": "CVE-2026-100255",
"lastModified": "2026-10-02T20:46:45.227",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9,
"source": "cve@jetbrains.com",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-100255",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-30T16:16:56.100",
"references": [
{
"source": "cve@jetbrains.com",
"tags": [
"Vendor Advisory"
],
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"sourceIdentifier": "cve@jetbrains.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1289"
}
],
"source": "cve@jetbrains.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | JetBrainsreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "TeamCity",
"vendor": "JetBrains",
"versions": [
{
"lessThan": "2026.2, \n2026.1.4, \n2025.11.8",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"source": "cve@jetbrains.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90B7BA91-8570-4A95-9C06-ABC6182E00A8",
"versionEndExcluding": "2025.11.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E68D7A2A-EDCD-4BEF-B205-F6000B6A9AA9",
"versionEndExcluding": "2026.1.4",
"versionStartIncluding": "2026.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "In JetBrains TeamCity before 2026.2, \n2026.1.4, \n2025.11.8 administrator account takeover was possible via password reset"
}
],
"id": "CVE-2026-100255",
"lastModified": "2026-10-02T20:46:45.227",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.9,
"source": "cve@jetbrains.com",
"type": "Secondary"
},
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9,
"source": "nvd@nist.gov",
"type": "Primary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-100255",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T00:00:00+00:00",
"version": "2.0.3"
}
}
]
},
"published": "2026-09-30T16:16:56.100",
"references": [
{
"source": "cve@jetbrains.com",
"tags": [
"Vendor Advisory"
],
"url": "https://www.jetbrains.com/privacy-security/issues-fixed/"
}
],
"sourceIdentifier": "cve@jetbrains.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1289"
}
],
"source": "cve@jetbrains.com",
"type": "Secondary"
}
]
}
} | — |
Every claim, by kind
vulnerability
| In JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 administrator account takeover was possible via password reset zetlyn/cve-nvd · 2026-09-30 | automatable no cvss 9.8 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cwe CWE-1289 exploitation none product TeamCity severity CRITICAL status Analyzed technical_impact total vendor JetBrains | source |
| In JetBrains TeamCity before 2026.2,
2026.1.4,
2025.11.8 administrator account takeover was... zetlyn/cve-ghsa · 2026-09-30 | cvss 8.1 cwe CWE-1289 severity high | source |