JetBrains Warns TeamCity Flaw Lets Unauthenticated Attackers Run Code, Rates CVE-2026-63077 at 9.8
Updated
Updated · InfoWorld · Jul 31
JetBrains Warns TeamCity Flaw Lets Unauthenticated Attackers Run Code, Rates CVE-2026-63077 at 9.8
2 articles · Updated · InfoWorld · Jul 31
Summary
JetBrains said CVE-2026-63077 lets attackers with HTTP(S) access bypass TeamCity authentication and execute operating system commands on on-premises servers.
Versions 2025.11.7 and 2026.1.3 fix the bug, while customers on TeamCity 2017.1 and later can deploy a security patch plugin if they cannot upgrade immediately.
The 9.8-severity flaw sits in the agent polling protocol and could expose credentials, alter server state, and compromise build artifacts and downstream CI/CD pipelines.
JetBrains said it has seen no active exploitation so far, but urged internet-exposed servers to restrict external access and run with minimal privileges; TeamCity Cloud customers need take no action.
With a critical 9.8 flaw exposing on-premise TeamCity servers, could your software supply chain already be silently compromised by attackers?
Why did TeamCity Cloud have protections against this catastrophic vulnerability while on-premises deployments were left completely exposed to remote takeovers?