Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
AdvisoryTeamCity On-PremisesOur summary
JetBrains has issued an urgent update for on-premise installations of TeamCity due to a severe vulnerability that could allow attackers to run arbitrary operating system commands without needing to log in. The flaw, tracked as CVE-2026-63077 (CVSS score: 9.8), impacts all prior versions of TeamCity On-Premises and was responsibly disclosed by Antoni Tremblay. Attackers with network access could exploit this issue to bypass authentication and execute code with the privileges of the TeamCity server process. JetBrains recommends upgrading to version 2025.11.7 or 2026.1.3 immediately, or applying a security patch plugin if updating is not feasible.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.