Particle.news
Download on the App Store

Critical Unauthenticated RCE Found in TeamCity On‑Premises

Attackers who can reach a TeamCity server over HTTP(S) can bypass authentication to run operating‑system commands.

Overview

  • JetBrains assigned CVE-2026-63077 for the flaw and published patched TeamCity releases 2025.11.7 and 2026.1.3 plus a security patch plugin for 2017.1 and newer while TeamCity Cloud instances were already mitigated.
  • The vulnerability exploits the TeamCity agent polling protocol so an unauthenticated caller with HTTP(S) access can bypass authentication and execute commands with the TeamCity server process privileges.
  • If an attacker succeeds, stored credentials, build configurations, and build artifacts can be exposed or altered and downstream CI/CD pipelines may be compromised depending on server privileges.
  • JetBrains says the issue was privately reported by researcher Antoni Tremblay and that there is no evidence of active exploitation at the time of the advisory.
  • Administrators should apply the patched releases or the security patch plugin immediately and harden exposure by requiring VPN or access controls and running the server with minimal operating‑system privileges.