CVE-2026-63077 — assigned a CVSS score of 9.8 — affects all TeamCity On-Premises releases and, JetBrains warns, “may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.”
What JetBrains reported and who found the flaw
JetBrains published an advisory urging customers running on-premise TeamCity servers to update immediately after a critical vulnerability was disclosed. The company credited Antoni Tremblay with discovering and reporting the issue on July 10, 2026. JetBrains has already updated TeamCity Cloud instances, and it published fixes for on-premise installations.
How the vulnerability enables remote command execution
According to JetBrains, the flaw allows unauthenticated remote code execution via the agent polling protocol. An attacker with HTTP(S) access to a vulnerable TeamCity server can use that protocol to sidestep authentication checks and execute arbitrary operating-system commands as the TeamCity server process. Depending on the privileges granted to that process, JetBrains said a successful compromise can lead to exposure of TeamCity data, configurations and stored credentials, or to modification of server state.
Fixed releases and a patch plugin for older installs
JetBrains addressed the vulnerability in TeamCity versions 2025.11.7 and 2026.1.3. For customers unable to upgrade immediately, the company released a security patch plugin that applies to TeamCity versions 2017.1 and later. JetBrains emphasized that “the security patch plugin will address only the vulnerability described above (CVE-2026-63077)” and reiterated that upgrading to the latest server version remains the recommended course to obtain additional security updates.
Impact on data and server integrity
Because the vulnerability executes commands with the privileges of the TeamCity server process, the advisory highlights two principal risks: unauthorized disclosure and unauthorized modification. JetBrains spelled out that an attacker who succeeds could expose TeamCity data, configurations and stored credentials; alternatively, an attacker could change server state. There is, at this time, no evidence that the flaw has been exploited in the wild, JetBrains said.
What this means for technologists, procurement teams, and administrators of internet-facing servers
- Technologists and security teams: Verify TeamCity versions and apply 2025.11.7 or 2026.1.3 where possible; if an immediate upgrade is infeasible, deploy the security patch plugin for versions 2017.1+. Monitor server privileges since the severity of any compromise depends on the TeamCity server process’s rights.
- Procurement and enterprise IT leaders: Ensure maintenance and update schedules include TeamCity servers and confirm cloud instances have already been updated. Consider timelines for upgrading legacy installations that still run older 2017-era releases despite the availability of a patch plugin.
- Administrators of internet-facing TeamCity servers: JetBrains recommends adding network controls — for example, requiring VPN connections or “implementing an extra layer of security to prevent unauthorized access to internet-facing TeamCity servers.” The company also warned that “Even exposing the TeamCity login screen or REST API can provide attackers with potential entry points to exploit newly disclosed vulnerabilities.”
JetBrains’ advisory supplies concrete fixes and mitigations: upgraded server releases, a targeted plugin for older versions, and guidance to restrict access to public-facing installations. With TeamCity Cloud already updated and no public evidence of exploitation so far, the immediate operational task is clear — patch or mitigate without delay. Whether organizations will prioritize upgrades or rely on the patch plugin is the next practical question; JetBrains’ own warning that the plugin addresses only CVE-2026-63077 strengthens the case for full upgrades.
Original report: The Hacker News




