Skip to content
Vulnerabilities

JetBrains Urging Customers to Patch Critical TeamCity Flaw that Enables OS Command Execution

JetBrains has urgently released security updates for a critical vulnerability in TeamCity On-Premises that could allow remote attackers to bypass authentication and execute arbitrary operating system commands. This vulnerability, tracked as CVE-2026-63077, affects all versions of TeamCity On-Premise...

· Jul 29, 2026 · 3 min read · 👁 1 views
JetBrains Urging Customers to Patch Critical TeamCity Flaw that Enables OS Command Execution

JetBrains has urgently released security updates for a critical vulnerability in TeamCity On-Premises that could allow remote attackers to bypass authentication and execute arbitrary operating system commands.

This vulnerability, tracked as CVE-2026-63077, affects all versions of TeamCity On-Premises. The company has addressed the issue in TeamCity versions 2025.11.7 and 2026.1.3.

Administrators who are unable to upgrade can install a dedicated security patch plugin, which is supported on TeamCity versions 2017.1 and later.

The vulnerability was privately reported on July 10, 2026, by security researcher Antoni Tremblay through JetBrains’ coordinated disclosure process.

JetBrains published an advisory on July 27 and stated that it is not aware of any active exploitation at the time of release. CVE-2026-63077 is an unauthenticated remote code execution flaw affecting TeamCity servers accessible via HTTP or HTTPS.

JetBrains also recently released security updates to address a critical code execution vulnerability in IntelliJ IDEA, alongside four high-severity vulnerabilities in TeamCity.

JetBrains TeamCity Vulnerability

According to JetBrains, an attacker can exploit the TeamCity agent polling protocol to bypass authentication checks. Successful exploitation would allow the attacker to run arbitrary commands with the permissions assigned to the TeamCity server process.

This level of access could pose serious risks to software development environments. An attacker might gain access to TeamCity project data, server configurations, stored credentials, and build settings.

They could also modify build jobs, tamper with generated artifacts, and potentially compromise downstream CI/CD pipelines.

The impact of this vulnerability depends on the privileges of the TeamCity service account. Servers running with elevated operating system permissions may expose more of the host and connected infrastructure to compromise.

Organizations that use TeamCity to manage production deployments, package signing, or cloud credentials should treat this flaw as a high-priority patching event.

JetBrains recommends that affected installations be upgraded to version 2025.11.7 or 2026.1.3 through a manual download or the TeamCity automatic update feature.

The patched releases fully fix CVE-2026-63077, and JetBrains has also released a security patch plugin for organizations that cannot upgrade immediately.

TeamCity versions 2024.03 and later can automatically download available security patch plugins and notify administrators when update notifications are enabled. Administrators can review patches under Administration, Updates, and Available Security Updates.

Users of TeamCity versions 2017.1 through 2018.1 must restart the server after installing the plugin. From TeamCity 2018.2 onward, administrators can enable the plugin without restarting the TeamCity server.

JetBrains emphasized that the plugin addresses only CVE-2026-63077 and is not a substitute for routine upgrades. TeamCity Cloud customers do not need to take any action, as JetBrains has already applied the necessary protections to their hosted environments.

As a defense-in-depth measure, organizations should restrict TeamCity access to trusted networks, place internet-facing instances behind a VPN or additional access-control layer, and run the TeamCity service with minimum required privileges.

JetBrains also recommends hosting TeamCity servers separately from build agents to reduce the potential impact of a compromise.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you

Are eSIMs Safe in 2026?
Data Breach

Are eSIMs Safe in 2026?

eSIM adoption is no longer a “nice-to-have” feature — it’s the default direction. More devices ship with stronger eSIM s...

S ShomoySoft Editorial · 26 min read · 10 ঘন্টা আগে