JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows attackers to bypass authentication and execute arbitrary commands remotely.
It affects all versions of TeamCity On-Premises. An attacker only requires HTTP or HTTPS access to a vulnerable TeamCity server to exploit this issue, with no need for a valid account, password, or prior access.
According to JetBrains, the flaw resides in the TeamCity agent polling protocol. A remote attacker can use this protocol to bypass authentication checks and execute operating system commands with the same privileges as the TeamCity server process.
This level of access poses serious risks for organizations that use TeamCity to manage software builds, releases, and CI/CD pipelines. A successful attack could expose stored credentials, configuration files, build data, and project secrets. Additionally, attackers could alter build settings, modify artifacts, or inject malicious code into downstream software releases.
JetBrains Vulnerability
JetBrains assigned the identifier CVE-2026-63077 to this issue after it was privately reported on July 10, 2026, by security researcher Antoni Tremblay through the company’s coordinated disclosure process.
The company has patched the vulnerability in TeamCity versions 2025.11.7 and 2026.1.3. Administrators are urged to download and install one of these versions immediately or use the built-in automatic update feature where available.
For organizations that cannot upgrade immediately, a dedicated security patch plugin can be installed. This plugin supports TeamCity versions 2017.1 and later and specifically addresses CVE-2026-63077.
However, JetBrains emphasizes that applying the plugin is only a temporary solution, as a full version upgrade also provides important security fixes.
For users of TeamCity version 2024.03 and later, the platform can automatically download available security patch plugins and, when notifications are enabled, notify administrators. Security updates can be checked from the Administration menu under Updates and Available Security Updates.
It’s important to note that servers running TeamCity versions 2017.1 through 2018.1 will require a restart after installing the plugin. In contrast, TeamCity version 2018.2 and later can enable the patch plugin without restarting the server.
JetBrains has confirmed that TeamCity Cloud customers do not need to take any action, as the company has already implemented protections in its cloud environments and found no evidence of exploitation of this flaw in TeamCity Cloud instances.
At the time of this announcement, JetBrains indicated that it was unaware of any active exploitation in the wild. Nevertheless, the risk of unauthenticated remote code execution makes immediate remediation crucial.
Administrators should also restrict TeamCity access to trusted networks, place internet-facing instances behind a VPN or another access control layer, and run the TeamCity service with minimal operating system privileges. Hosting TeamCity servers separately from build agents can further mitigate the impact of a potential compromise.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

