JetBrains Patches Critical TeamCity On-Premises Vulnerability

TeamCity On-Premises vulnerability CVE-2026-63077 authentication bypass

Build systems rarely capture public attention; however, unauthorized access opens a direct pathway to source code, credentials, and compiled software. Amid this serious threat, JetBrains released an urgent security update addressing a critical flaw in all TeamCity On-Premises versions.

Understanding CVE-2026-63077 and Its Severe Impact

Designated as CVE-2026-63077, this flaw carries a near-maximum CVSS 3.1 severity score of 9.8. The vulnerability allows unauthenticated remote attackers to bypass authentication mechanisms via TeamCity’s agent polling protocol. Consequently, adversaries can execute arbitrary operating system commands with the privileges of the TeamCity process simply by accessing the server over HTTP or HTTPS.

A successful compromise can expose server configuration data, stored credentials, and sensitive secrets. Furthermore, attackers can manipulate system state, alter build artifacts, and compromise downstream CI/CD pipelines used to test and deploy software.

Affected Versions and Official Mitigation Options

This security flaw affects all local TeamCity installations. JetBrains resolved the issue within versions 2025.11.7 and 2026.1.3. For instances running TeamCity 2017.1 or newer that cannot undergo immediate upgrades, the vendor released a standalone security plugin. According to JetBrains’ security advisory on CVE-2026-63077, this plugin specifically mitigates this flaw but does not replace full software updates.

Discovery Timeline and Defense Recommendations

Security researcher Anthony Tremblay reported the vulnerability to JetBrains on July 10, 2026, under coordinated disclosure protocols. Currently, JetBrains reports no evidence of active exploitation in the wild. Moreover, TeamCity Cloud customers require no action, as protective measures were applied automatically.

Administrators should update TeamCity On-Premises installations to version 2025.11.7 or 2026.1.3 immediately or install the security plugin. Additionally, organizations should restrict server access to trusted networks or VPNs, run TeamCity with minimal process privileges, and isolate server infrastructure from build agents.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply