JetBrains patches critical TeamCity bug allowing unauthenticated server takeover

CI/CD platforms have become prime targets for attackers seeking supply chain access, and JetBrains’ latest security advisory underscores the risk.

CSBadmin
2 Min Read

CI/CD platforms have become prime targets for attackers seeking supply chain access, and JetBrains’ latest security advisory underscores the risk. The company disclosed a critical unauthenticated remote code execution vulnerability in TeamCity On-Premises on Tuesday, assigning CVE-2026-63077 a CVSS severity score of 9.8.

The flaw resides in TeamCity’s agent polling protocol, which normally lets build agents check in for work. An attacker who can reach the server via HTTP or HTTPS can craft requests that slip past all authentication checks and run operating system commands at the privilege level of the running TeamCity process. Any data the process can read — including stored credentials, pipeline definitions, build artifacts, and configuration settings — becomes accessible from that position.

Data exfiltration and downstream infection are both on the table when a CI/CD server falls. JetBrains solutions engineering lead Daniel Gallo described a worst-case scenario where an exploit “could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI/CD pipelines.”

Researcher Antoni Tremblay privately reported the flaw earlier this month. JetBrains said it found no exploitation attempts against its Cloud-hosted instances, but past campaigns by nation-state hackers and ransomware groups against TeamCity servers underscore the risk of delaying patches.

For Cloud customers, the fix was applied server-side with no action required. On-premises administrators must move to build 2025.11.7 or 2026.1.3; those on legacy versions can deploy a dedicated security patch plugin compatible with TeamCity 2017.1 and later. Hardening measures include placing TeamCity behind restricted network access, enforcing VPN-only connectivity for exposed instances, and stripping the service account down to the minimum OS permissions needed for normal operation.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.