


Perceptive Security
SOC/SIEM Consultancy

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Published:
28 July 2026 at 08:11:22
Alert date:
28 July 2026 at 10:01:48
Source:
thehackernews.com
Enterprise Applications, Zero-Day Vulnerabilities, Identity & Access
JetBrains has disclosed a critical security vulnerability in TeamCity On-Premises identified as CVE-2026-63077 with a CVSS score of 9.8. The flaw affects all on-premises versions of TeamCity and could allow unauthenticated attackers to execute arbitrary OS commands. JetBrains has released patched versions 2025.11.7 and 2026.1.3 to address the issue. TeamCity Cloud instances have already been patched. Users of on-premises installations are strongly urged to update immediately. The vulnerability is particularly dangerous due to the lack of authentication requirement for exploitation, making it accessible to any remote attacker.
Technical details
CVE-2026-63077 is a critical vulnerability (CVSS 9.8) in JetBrains TeamCity On-Premises affecting all versions. The flaw allows an unauthenticated attacker with HTTP(S) access to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. Exploitation is achieved via the agent polling protocol to sidestep authentication checks. A successful compromise can lead to exposure of TeamCity data, configurations, and stored credentials, or modification of server state. There is no evidence of exploitation in the wild at the time of disclosure. The vulnerability was discovered and reported by Antoni Tremblay on July 10, 2026.
Mitigation steps:
1. Update JetBrains TeamCity On-Premises to version 2025.11.7 or 2026.1.3. 2. For instances that cannot be immediately updated (versions 2017.1+), apply the security patch plugin available at the JetBrains download link. 3. TeamCity Cloud instances have already been patched automatically. 4. Require VPN connections for access to internet-facing TeamCity servers. 5. Implement an extra layer of security to prevent unauthorized access. 6. Avoid exposing the TeamCity login screen or REST API directly to the internet to minimize attack surface for future vulnerabilities. 7. Upgrade to the latest version to benefit from all available security updates beyond just this specific fix.
Affected products:
JetBrains TeamCity On-Premises - all versions prior to 2025.11.7 and 2026.1.3
JetBrains TeamCity On-Premises 2017.1+ (security patch plugin available)
Related links:
https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/
https://download.jetbrains.com/teamcity/plugins/internal/fix_CVE_2026_63077.zip
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
