JETBRAINS has disclosed three vulnerabilities across JetBrains Exposed and TeamCity that could let an attacker run arbitrary code or manipulate databases on affected servers. The flaws were assigned CVEs CVE-2026-108474 (highest severity 9.8, CWE-89), CVE-2026-106218 (CWE-184), and CVE-2026-106219 (CWE-73). The report states there is no confirmed exploitation at present, but patches have been released and administrators are urged to apply them promptly.
The most serious issue lies in the Exposed framework, which fails to escape string arguments in several SQL functions, enabling unauthenticated SQL command injection. TeamCity is affected by two separate problems: (1) the application does not validate Git submodule URLs, potentially allowing reading of local repositories on the server; and (2) a sandbox escape in the Kotlin DSL integration could allow code execution on the TeamCity host.
The affected software versions are Exposed prior to 1.5.1; TeamCity prior to 2026.2.1 (and specifically the code execution fix targets TeamCity 2026.1.3 and 2025.11.7 as a minimum for older branches).
Mitigation guidance calls for updating Exposed to version 1.5.1 and upgrading TeamCity to 2026.2.1 immediately; users on older TeamCity branches should move to at least 2025.11.7 to address the code‑execution flaw. The report notes that no exploitation has been publicly confirmed and that JetBrains’ advisories should be consulted for precise patch details.