Overview
- JetBrains assigned CVE-2026-63077 for the flaw and published patched TeamCity releases 2025.11.7 and 2026.1.3 plus a security patch plugin for 2017.1 and newer while TeamCity Cloud instances were already mitigated.
- The vulnerability exploits the TeamCity agent polling protocol so an unauthenticated caller with HTTP(S) access can bypass authentication and execute commands with the TeamCity server process privileges.
- If an attacker succeeds, stored credentials, build configurations, and build artifacts can be exposed or altered and downstream CI/CD pipelines may be compromised depending on server privileges.
- JetBrains says the issue was privately reported by researcher Antoni Tremblay and that there is no evidence of active exploitation at the time of the advisory.
- Administrators should apply the patched releases or the security patch plugin immediately and harden exposure by requiring VPN or access controls and running the server with minimal operating‑system privileges.