Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Summary
JetBrains has released critical updates for its TeamCity on-premise software following the discovery of a severe vulnerability that allows arbitrary code execution without requiring a login. The flaw, tracked as CVE-2026-63077, has a CVSS score of 9.8 and affects all on-premise TeamCity versions prior to the patched releases.
IFF Assessment
This vulnerability allows attackers to execute arbitrary code on affected systems, posing a significant threat to defenders.
Severity
The CVSS score of 9.8 indicates a critical severity, highlighting that the vulnerability allows for arbitrary code execution without authentication, which has a high impact on confidentiality, integrity, and availability.
Defender Context
This critical vulnerability in TeamCity, a popular CI/CD tool, allows unauthenticated attackers to run OS commands, which could lead to full system compromise. Defenders should prioritize patching all on-premise TeamCity instances immediately and monitor for any signs of exploitation.