Tag: Logging In

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
News

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

After a serious security flaw that could lead to arbitrary code execution was found, JetBrains is advising users of on-premise TeamCity versions to update to the most recent version. The vulnerability, designated CVE-2026-63077 (CVSS score: 9.8), impacts every version of TeamCity On-Premises. Versions 2025.11.7 and 2026.1.3 have addressed it. Instances of TeamCity Cloud have already been updated. On July 10, 2026, Antoni Tremblay discovered and reported the flaw, according to JetBrains. According to JetBrains, if this vulnerability is exploited, an unauthenticated attacker with HTTP(S) access to a TeamCity server could get around authentication checks and use the privileges of the TeamCity server process to carry out arbitrary operating system commands. The vulnerability makes it...