CVE Tools

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

The Hacker NewsBy The Hacker News

AdvisoryTeamCity On-Premises

Our summary

JetBrains has issued an urgent update for on-premise installations of TeamCity due to a severe vulnerability that could allow attackers to run arbitrary operating system commands without needing to log in. The flaw, tracked as CVE-2026-63077 (CVSS score: 9.8), impacts all prior versions of TeamCity On-Premises and was responsibly disclosed by Antoni Tremblay. Attackers with network access could exploit this issue to bypass authentication and execute code with the privileges of the TeamCity server process. JetBrains recommends upgrading to version 2025.11.7 or 2026.1.3 immediately, or applying a security patch plugin if updating is not feasible.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store