Critical JetBrains TeamCity CVE-2024-27198 Flaw Lets Attackers Run OS Commands
Key Takeaways A critical remote code execution vulnerability (CVE-2026-63077) has been discovered in JetBrains TeamCity On-Premises. The flaw allows unauthenticated attackers to bypass security...
Key Takeaways
- A critical remote code execution vulnerability (CVE-2026-63077) has been discovered in JetBrains TeamCity On-Premises.
- The flaw allows unauthenticated attackers to bypass security measures and execute arbitrary commands on the operating system.
- All versions of TeamCity On-Premises are affected, posing significant risks to software development and CI/CD pipelines.
- JetBrains has released urgent security updates (versions 2025.11.7 and 2026.1.3) and a dedicated security patch plugin.
JetBrains has issued an urgent security advisory and released critical updates to address a severe vulnerability in its TeamCity On-Premises continuous integration/continuous delivery (CI/CD) server. The flaw, identified as CVE-2026-63077, could enable remote attackers to circumvent authentication protocols and execute arbitrary commands on the underlying operating system.
Table Of Content
This critical vulnerability impacts all versions of TeamCity On-Premises. JetBrains has released patched versions 2025.11.7 and 2026.1.3 to mitigate the risk. For administrators unable to perform a full upgrade immediately, a specific security patch plugin is available, compatible with TeamCity versions 2017.1 and newer.
The vulnerability was initially reported on July 10, 2026, by security researcher Antoni Tremblay through JetBrains’ coordinated disclosure program. JetBrains published its official advisory on July 27, confirming that at the time of release, there was no awareness of active exploitation. CVE-2026-63077 is characterized as an unauthenticated remote code execution (RCE) vulnerability, affecting TeamCity servers accessible via HTTP or HTTPS.
This incident follows other recent security updates from JetBrains, including fixes for a critical code execution vulnerability in IntelliJ IDEA and four high-severity flaws within TeamCity itself.
Understanding the TeamCity Vulnerability
According to JetBrains, the vulnerability stems from a weakness in the TeamCity agent polling protocol, which an attacker can exploit to bypass critical authentication checks. Successful exploitation grants the attacker the ability to run arbitrary commands with the same permissions as the TeamCity server process.
Such a level of access presents profound risks to software development environments. An attacker could potentially gain unauthorized access to sensitive TeamCity project data, server configurations, stored credentials, and critical build settings. Furthermore, they could modify build jobs, tamper with generated artifacts, and compromise downstream CI/CD pipelines, leading to supply chain integrity issues.
The severity of the impact is directly proportional to the privileges assigned to the TeamCity service account. Servers operating with elevated operating system permissions are particularly vulnerable, potentially exposing a broader segment of the host system and connected infrastructure to compromise. Organizations leveraging TeamCity for critical operations such as managing production deployments, package signing, or cloud credentials must prioritize patching this flaw.
Mitigation and Updates
JetBrains strongly recommends that affected installations be upgraded to either version 2025.11.7 or 2026.1.3. These updates can be applied through a manual download or via TeamCity’s automatic update feature. The patched releases fully resolve CVE-2026-63077. For instances where an immediate full upgrade is not feasible, JetBrains has also released a security patch plugin.
TeamCity versions 2024.03 and later can automatically download available security patch plugins and alert administrators if update notifications are enabled. Administrators can access these patches under the “Administration,” “Updates,” and “Available Security Updates” sections. Users of TeamCity versions 2017.1 through 2018.1 will need to restart their server after installing the plugin. However, for TeamCity 2018.2 and newer, the plugin can be enabled without a server restart.
JetBrains has clarified that while the plugin addresses CVE-2026-63077 specifically, it is not a substitute for regular software upgrades. TeamCity Cloud customers are not required to take any action, as JetBrains has already implemented the necessary protections on its hosted environments.
What You Should Do
- Upgrade Immediately: Update TeamCity On-Premises to versions 2025.11.7 or 2026.1.3 as soon as possible.
- Install Patch Plugin: If immediate upgrade is not feasible, install the dedicated security patch plugin, available for TeamCity versions 2017.1 and later.
- Restart Server (if applicable): For TeamCity versions 2017.1 through 2018.1, restart the server after installing the plugin.
- Implement Defense-in-Depth: Restrict TeamCity access to trusted networks, place internet-facing instances behind a VPN or additional access-control layer, and run the TeamCity service with the minimum necessary privileges.
- Isolate Servers: Host TeamCity servers separately from build agents to minimize the potential impact of a compromise.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.