By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Critical TeamCity Flaw Allows OS Command Execution Without Login

JetBrains has issued an urgent advisory for users of its on-premise TeamCity continuous integration and continuous delivery (CI/CD) server, detailing a critical security vulnerability that could permit attackers to execute operating system commands without requiring any form of authentication. This significant flaw, officially designated as CVE-2026-63077, carries a high severity score of 9.8 on the Common Vulnerability Scoring System (CVSS), indicating a severe risk to affected systems. The vulnerability impacts all versions of TeamCity On-Premises. JetBrains has already released patches to address this issue, with fixes available in TeamCity versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances, which are managed by JetBrains, have reportedly been secured against this particular threat. The company strongly recommends that all customers running the on-premise version of TeamCity immediately upgrade to one of the patched versions to mitigate the risk of exploitation. Failure to do so could expose sensitive systems and data to unauthorized access and malicious control. The nature of the vulnerability suggests that an unauthenticated attacker could potentially gain a foothold within the server's operating system, enabling them to run arbitrary code. This could lead to a wide range of damaging activities, including data theft, system disruption, the deployment of ransomware, or the use of the compromised server as a pivot point for further attacks within a network. TeamCity is a widely used platform in software development environments, facilitating automated builds, testing, and deployments. Its compromise could therefore have far-reaching consequences for organizations relying on it for their development pipelines. The prompt remediation by JetBrains, including the swift release of patches and clear communication to customers, underscores the severity of the discovered vulnerability. Users are advised to consult the official JetBrains security advisory for detailed instructions on applying the updates and verifying their system's security status. The company's proactive stance in addressing such critical issues is crucial for maintaining trust and security within the developer community that relies on its tools for essential software development operations. The specific technical details of how the arbitrary code execution is achieved without authentication have not been fully disclosed by JetBrains, likely to prevent aiding potential attackers, but the CVSS score and the nature of the threat are clear indicators of the potential damage. Organizations using TeamCity should prioritize this update to safeguard their development infrastructure and prevent potential security breaches.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.