JetBrains TeamCity Unauthenticated RCE Vulnerability Patched (CVE-2026-63077)

www.news4hackers.com-jetbrains-teamcity-unauthenticated-rce-vulnerability-patched-cve-2026-63077--jetbrains-teamcity-unauthenticated-rce-vulnerability-patched-cve-2026-63077-

JetBrains addresses critical unauthenticated remote code execution flaw in TeamCity On-Premises (CVE-2026-63077)

Details of the vulnerability

Discovered and reported privately earlier this month by security researcher Antoni Tremblay, CVE-2026-63077 leverages the TeamCity agent polling protocol to bypass authentication mechanisms. This flaw enables threat actors to execute operating system commands with the privileges of the TeamCity server process. Depending on the permissions assigned to the server, exploitation could lead to data exposure, configuration manipulation, credential theft, and compromise of build artifacts and downstream CI/CD workflows, as explained by Gallo.

Mitigation steps

TeamCity On-Premises users are required to upgrade to version 2025.11.7 or 2026.1.3, or apply the security patch plugin if running versions v2017.1 and above. Administrators using v2017.1 to v2018.1 must restart the server after patch installation, whereas versions v2018.2 and later allow plugin activation without this step. To reduce exposure risks, JetBrains suggests restricting network access to TeamCity servers to trusted environments. For internet-facing deployments, implementing VPN requirements or additional security layers is recommended.

The company emphasized that even limited access to the TeamCity login interface or REST API could provide attackers with entry points for exploiting newly disclosed vulnerabilities. Further security measures include operating the TeamCity server with the least necessary system privileges to minimize potential damage from successful attacks.

Advisory summary

The advisory underscores the importance of proactive patch management for CI/CD infrastructure, highlighting the potential consequences of unaddressed vulnerabilities in critical development workflows.


Blog Image

About Author

en_USEnglish