External risk intelligence

JetBrains TeamCity Administrator Account Takeover via Password Reset

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-100255

JetBrains TeamCity is a continuous integration and deployment server typically deployed as a centralized, web-based management service. It is commonly configured to be accessible over the network to facilitate developer and build-agent access, making it a frequent candidate for internet-facing or edge-service deployment.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in JetBrains TeamCity allows an attacker to take over an administrator account through a password reset flaw, potentially impacting systems that manage software development pipelines. The main concern is confirming relevance and exposure within our environment.

  • Flaw allows unauthorized administrator access.
  • Secures critical development and deployment processes.
  • Confirm your TeamCity instances are not exposed.

Attack Path

How an attacker could exploit the issue

An attacker could gain administrative control of JetBrains TeamCity by exploiting a flaw in the password reset functionality. This could allow them to take over accounts, potentially leading to widespread compromise of the system and its data.

  • No authentication required to start.
  • Triggered via password reset mechanism.
  • Results in administrator account takeover.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an administrator account takeover could be possible, potentially affecting the integrity and confidentiality of the TeamCity service.

  • Administrator account access.
  • Password reset flaw.
  • System compromise and data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in JetBrains TeamCity affects the administrator account, posing a critical risk of takeover. Responsibility likely falls on the application owner and potentially the platform or infrastructure teams to identify all TeamCity instances, determine their exposure, and coordinate remediation. The first practical step is to locate all TeamCity deployments, confirm their reachability and business criticality, and then engage the appropriate teams for a planned fix, prioritizing instances that are publicly accessible or handle sensitive data.

  • Application owners must own this issue.
  • Verify all TeamCity instance exposure.
  • Plan and coordinate administrative access remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is JetBrains TeamCity?

TeamCity is a continuous integration and deployment server used by software development teams to automate building, testing, and deploying applications. It acts as a centralized hub that manages complex software pipelines, allowing developers and automated build agents to collaborate and push code into production environments efficiently.

What does CVE-2026-100255 mean?

This CVE identifies a security weakness classified as CWE-1289, which involves improper validation of data during a password reset. In plain terms, the vulnerability allows an unauthorized person to bypass standard verification checks, effectively letting them reset an administrator's password and gain full control over the application without needing prior login credentials.

How is the TeamCity password reset flaw triggered?

The flaw is triggered by interacting with the password recovery process. Because the vulnerability lies within how the system handles these reset requests, it does not require an attacker to have a pre-existing account or administrative privileges to initiate the process. Normal user activity that does not involve the specific password reset mechanism is not affected by this bug.

Is my TeamCity instance at risk?

According to Halo Surface Signal, TeamCity is often deployed as a web-based service accessible over the network for developer access. If your instance is reachable from the internet, it faces a higher likelihood of being targeted. You should prioritize assessing any TeamCity deployments that are not restricted to your internal network.

Do I need to patch TeamCity immediately?

Yes, because this vulnerability grants administrative takeover, you should act quickly. Start by identifying all instances of TeamCity in your environment to understand which are exposed. Once located, coordinate with your technical teams to update to the safe versions listed in the vendor advisory to resolve the password reset flaw.

References