


Perceptive Security
SOC/SIEM Consultancy

JetBrains warns of critical TeamCity remote code execution flaw
Published:
31 juli 2026 om 00:01:31
Alert date:
31 juli 2026 om 01:02:24
Source:
bleepingcomputer.com
Enterprise Applications, Zero-Day Vulnerabilities, Supply Chain & Dependencies
JetBrains has issued a warning about a critical authentication bypass vulnerability in TeamCity On-Premises. The flaw could allow unauthenticated attackers to achieve remote code execution on affected servers. TeamCity is a widely used CI/CD platform, making this vulnerability particularly impactful for development and enterprise environments. JetBrains has urged administrators to apply patches immediately. The vulnerability poses significant risk as TeamCity servers are often accessible from the internet and contain sensitive source code and build pipeline configurations. This type of authentication bypass combined with RCE capability is considered critical severity.
Technical details
CVE-2026-63077 is a critical authentication bypass vulnerability in JetBrains TeamCity On-Premises. An attacker with HTTPS access to a TeamCity server can bypass authentication via the agent polling protocol and execute arbitrary operating system commands with the privileges of the server process. Successful exploitation can expose TeamCity data, configurations, stored credentials, or compromise build artifacts and CI/CD pipelines depending on privileges. All versions of TeamCity On-Premises are affected. TeamCity Cloud is not affected. The vulnerability was privately reported on July 10 and the advisory was published on July 27, with no evidence of active exploitation at time of publication.
Mitigation steps:
1. Upgrade TeamCity On-Premises to versions 2025.11.7 or 2026.1.3 as the primary remediation. 2. For customers unable to upgrade, install the security patch plugin available for TeamCity 2017.1+. 3. Note that TeamCity versions 2017.1 through 2018.1 require a server restart after installing the patch plugin. 4. TeamCity 2024.03 and newer automatically downloads available security patch plugins and notifies administrators for installation. 5. Require VPN access or other protective layers on internet-facing TeamCity servers. 6. Avoid exposing the TeamCity login page or REST API directly to the internet. 7. TeamCity Cloud customers do not need to take any action as patches have already been applied.
Affected products:
JetBrains TeamCity On-Premises - All versions (patch available for 2017.1+
fixed in 2025.11.7 and 2026.1.3)
Related links:
http://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/
https://www.bleepingcomputer.com/news/security/critical-teamcity-flaw-now-widely-exploited-to-create-admin-accounts/
https://www.bleepingcomputer.com/news/security/ransomware-gangs-now-exploiting-critical-teamcity-rce-flaw/
https://www.bleepingcomputer.com/news/security/north-korean-hackers-exploit-critical-teamcity-flaw-to-breach-networks/
https://www.jetbrains.com/help/teamcity/installing-additional-plugins.html#Installing+Plugin+via+Web+UI
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
