<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Critical JetBrains TeamCity Flaw Lets Attackers Run Commands Without Logging In

JetBrains fixes critical TeamCity flaw allowing remote command execution. Upgrade now to secure stored credentials and configuration files.
Content Team

JetBrains has patched a critical vulnerability (CVE-2026-63077) in TeamCity On-Premises that lets attackers execute OS commands remotely — no credentials required. All versions are affected. An attacker only needs HTTP or HTTPS access to exploit the flaw, which lives in the TeamCity agent polling protocol.

A successful attack could expose stored credentials, build secrets, and configuration files, or allow code injection into software releases. Security researcher Antoni Tremblay privately reported the issue on July 10, 2026.

Fixed versions 2025.11.7 and 2026.1.3 are available now. Admins who can't upgrade immediately can install a temporary security patch plugin. TeamCity Cloud users are already protected.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo