JetBrains has warned of a critical TeamCity remote code execution vulnerability that affects all versions of TeamCity On-Premises.

The flaw, tracked as CVE-2026-63077, allows an attacker with HTTPS access to a vulnerable TeamCity server to bypass authentication and execute operating system commands with the server process’s privileges.

JetBrains has released fixed versions and urged administrators to update as soon as possible.

Authentication bypass can lead to code execution

CVE-2026-63077 affects the agent polling protocol in TeamCity On-Premises. An attacker could exploit the issue to bypass authentication and run arbitrary commands on the server.

TeamCity is a continuous integration and continuous delivery platform used to build, test and deploy software. As a result, a successful compromise could expose sensitive development infrastructure.

Depending on the affected account and server privileges, attackers may gain access to TeamCity data, configurations and stored credentials. They could also compromise build artefacts or CI/CD pipelines.

JetBrains said TeamCity Cloud customers do not need to take action because the required protections have already been applied.

No active exploitation reported

The flaw was privately reported to JetBrains on 10 July. When the company published its advisory on 27 July, it said it had no evidence of active exploitation.

However, TeamCity servers have been targeted repeatedly in the past. Ransomware gangs and state-backed threat actors have exploited earlier TeamCity vulnerabilities to gain access to corporate networks.

That history makes rapid patching especially important for organisations with internet-facing TeamCity instances.

Upgrade TeamCity or install the security plugin

JetBrains fixed the issue in TeamCity versions 2025.11.7 and 2026.1.3. Upgrading to one of those releases is the recommended option.

Customers unable to upgrade can install a security patch plugin. The plugin is available for TeamCity versions 2017.1 and later.

TeamCity versions 2024.03 and newer automatically download available security patch plugins. Administrators then receive a notification to install the update.

Servers running TeamCity 2017.1 through 2018.1 must be restarted after installing the patch plugin for the fix to take effect.

Protect internet-facing TeamCity servers

JetBrains also advised administrators to restrict access to TeamCity servers. Using a VPN or another protective layer can reduce exposure for systems that are reachable from the internet.

The company noted that exposing the TeamCity login page or REST API can provide attackers with an entry point when a new vulnerability is disclosed.

Administrators should patch affected servers immediately, review who can access the platform and avoid leaving TeamCity management services directly exposed online.


0 responses to “JetBrains Warns of Critical TeamCity Remote Code Execution Flaw”