Skip to content

JetBrains warns of critical unauthenticated RCE vulnerability in TeamCity

The essentials: Unauthenticated remote code execution in TeamCity via malformed HTTP requests to the agent polling protocol requires immediate patching or plugin installation.

JetBrains has disclosed a critical security vulnerability (CVE-2026-63077) in the TeamCity DevOps platform that allows attackers without authentication to execute arbitrary commands on affected servers. The flaw impacts all TeamCity on-premises installations and stems from a deserialization issue in the agent polling protocol.

The vulnerability carries a CVSS rating of 9.8 and requires neither authentication nor user interaction. An attacker with HTTP(S) access to a TeamCity server can leverage the authentication bypass and execute code with the privileges of the TeamCity server process. The flaw is classified as CWE-502 (deserialization of untrusted data) and is triggered by specially crafted data in the agent polling protocol.

For security leaders, successful exploitation poses significant risks: TeamCity data, configurations, and stored credentials can be exposed; server state can be manipulated and the integrity of build artifacts and downstream CI/CD pipelines compromised. Particularly critical is the exposure of build environments and software supply chains.

JetBrains has recommended two migration paths. Organizations should upgrade to TeamCity 2025.11.7 or 2026.1.3, which contain a permanent fix. If immediate upgrades are not feasible, a security patch plugin is available for TeamCity 2017.1 and newer. Versions 2017.1 through 2018.1 require a restart after installation, while newer supported versions can enable the fix without restarting.

As interim measures, CISOs should isolate publicly accessible TeamCity servers from the internet and restrict access to trusted networks. Official security best practice mandates that TeamCity servers run on dedicated hosts separate from build agents and with minimal operating system privileges. The vulnerability was reported on 10 July 2024 by security researcher Antoni Tremblay through JetBrains’ coordinated disclosure process. At the time of advisory publication, no active exploitation was documented. TeamCity Cloud customers are unaffected.


Source: www.csoonline.com · Published 31 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: