Back to News
Vulnerabilities

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

Cyber RTJuly 28, 20263 min read
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

JetBrains urges customers to update on-premise TeamCity versions due to a critical security flaw (CVE-2026-63077, CVSS score: 9.8) allowing unauthenticated code execution. The issue affects all TeamCity On-Premises versions and is fixed in versions 2025.11.7 and 2026.1.3. A security patch plugin is available for older versions. No exploitation evidence exists. Customers should enhance security measures, like VPNs, to protect servers.

JetBrains has issued an urgent advisory for users of the on-premise versions of TeamCity, urging them to update to the latest version due to a critical security vulnerability. This flaw, identified as CVE-2026-63077 with a CVSS score of 9.8, poses a significant risk as it could allow arbitrary code execution. The vulnerability impacts all versions of TeamCity On-Premises, but has been addressed in the newly released versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated to mitigate this issue. The vulnerability was discovered and reported by Antoni Tremblay on July 10, 2026. JetBrains explained that if this flaw is exploited, it could enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks. This would allow the attacker to execute arbitrary operating system commands with the same privileges as the TeamCity server process, posing a severe security threat. The flaw specifically allows for unauthenticated remote code execution through the agent polling protocol, effectively bypassing authentication checks to achieve command execution. The extent of the compromise depends on the privileges of the TeamCity server process. A successful attack could lead to the exposure of sensitive TeamCity data, configurations, stored credentials, or even modification of the server state, potentially causing significant damage. To address this critical issue, JetBrains has not only released updated versions but also a security patch plugin for versions 2017.1 and later. This plugin is intended for customers who are unable to immediately update their systems, allowing them to patch their environments against this specific vulnerability. JetBrains has emphasized that there is currently no evidence of this flaw being exploited in the wild. JetBrains has also highlighted the importance of applying the security patch plugin, noting that it specifically addresses CVE-2026-63077. However, they strongly recommend upgrading to the latest version to benefit from a broader range of security updates. This proactive approach is crucial for maintaining the security integrity of TeamCity servers. As part of best security practices, JetBrains advises customers to consider implementing additional security measures, such as requiring VPN connections or adding extra layers of security. This is particularly important for preventing unauthorized access to internet-facing TeamCity servers, which could otherwise be vulnerable to exploitation. JetBrains further cautions that even exposing the TeamCity login screen or REST API can provide attackers with potential entry points to exploit newly disclosed vulnerabilities. Therefore, securing these elements is essential to protect against potential threats. For those interested in staying updated on similar security issues and exclusive content, JetBrains encourages following their updates on platforms like Google News, Twitter, and LinkedIn. This ensures users are informed about the latest developments and security advisories.