JetBrains says a crafted HTTP request could break TeamCity
Summary
JetBrains has disclosed a critical vulnerability in its TeamCity DevOps platform, identified as CVE-2026-63077, which allows unauthenticated attackers to execute arbitrary operating system commands. The flaw affects TeamCity On-Premises deployments and has been patched in recent versions, with a security patch plugin available for those unable to upgrade immediately.
IFF Assessment
This vulnerability allows unauthenticated attackers to execute arbitrary commands, posing a significant threat to systems and data.
Severity
The CVSS score of 9.8 reflects the critical nature of the vulnerability, as it requires no authentication or user interaction for exploitation, leading to remote code execution.
Defender Context
Defenders should prioritize patching TeamCity On-Premises deployments immediately to mitigate the risk of unauthenticated RCE. Monitoring for any signs of exploitation targeting the agent polling protocol is crucial, especially for internet-exposed instances.