The Bottom Line: An authentication vulnerability in TeamCity On-Premises allows unauthenticated access with remote code execution capability.
JetBrains warns of a critical authentication vulnerability in TeamCity On-Premises that enables remote code execution. Affected organizations should update to patched versions as quickly as possible.
JetBrains has publicly disclosed a critical authentication vulnerability in TeamCity On-Premises that allows attackers to bypass access controls and execute commands on the affected system. As a central build and deployment platform in many CI/CD pipelines, TeamCity represents a preferred target – compromising it would result in direct access to production infrastructure and code repositories.
The vulnerability allows unauthenticated attackers to execute actions without valid credentials and run arbitrary code on the TeamCity instance. This affects locally operated installations and opens pathways to lateral movement, data theft, or sabotage of build pipelines.
JetBrains has released patches. CISOs should immediately verify which TeamCity versions are deployed in their environment and update them to patched releases. As a standard practice, logs should also be reviewed for access patterns that indicate exploitation of the vulnerability prior to patch availability.
Source: www.bleepingcomputer.com · Published 31 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.