Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

Summary

JetBrains has released critical updates for its TeamCity on-premise software following the discovery of a severe vulnerability that allows arbitrary code execution without requiring a login. The flaw, tracked as CVE-2026-63077, has a CVSS score of 9.8 and affects all on-premise TeamCity versions prior to the patched releases.

IFF Assessment

FOE

This vulnerability allows attackers to execute arbitrary code on affected systems, posing a significant threat to defenders.

Severity

9.8 Critical

The CVSS score of 9.8 indicates a critical severity, highlighting that the vulnerability allows for arbitrary code execution without authentication, which has a high impact on confidentiality, integrity, and availability.

Defender Context

This critical vulnerability in TeamCity, a popular CI/CD tool, allows unauthenticated attackers to run OS commands, which could lead to full system compromise. Defenders should prioritize patching all on-premise TeamCity instances immediately and monitor for any signs of exploitation.

Read Full Story →