JetBrains says a crafted HTTP request could break TeamCity

Summary

JetBrains has disclosed a critical vulnerability in its TeamCity DevOps platform, identified as CVE-2026-63077, which allows unauthenticated attackers to execute arbitrary operating system commands. The flaw affects TeamCity On-Premises deployments and has been patched in recent versions, with a security patch plugin available for those unable to upgrade immediately.

IFF Assessment

FOE

This vulnerability allows unauthenticated attackers to execute arbitrary commands, posing a significant threat to systems and data.

Severity

9.8 Critical

The CVSS score of 9.8 reflects the critical nature of the vulnerability, as it requires no authentication or user interaction for exploitation, leading to remote code execution.

Defender Context

Defenders should prioritize patching TeamCity On-Premises deployments immediately to mitigate the risk of unauthenticated RCE. Monitoring for any signs of exploitation targeting the agent polling protocol is crucial, especially for internet-exposed instances.

Read Full Story →