JetBrains warns of critical TeamCity remote code execution flaw

JetBrains warns of critical TeamCity remote code execution flaw
JetBrains has disclosed a critical authentication bypass in TeamCity On-Premises, tracked as CVE-2026-63077, that could let attackers achieve remote code execution over HTTPS. The flaw affects all on-premises versions, while TeamCity Cloud is not impacted and already protected. #JetBrains #TeamCity #CVE-2026-63077

Keypoints

  • CVE-2026-63077 allows authentication bypass in TeamCity On-Premises.
  • An attacker can execute arbitrary OS commands with server-process privileges.
  • All TeamCity On-Premises versions are affected.
  • JetBrains fixed the issue in versions 2025.11.7 and 2026.1.3.
  • Administrators should upgrade or apply the security patch plugin immediately.

Read More: https://www.bleepingcomputer.com/news/security/jetbrains-warns-of-critical-teamcity-remote-code-execution-flaw/