JetBrains warns of critical TeamCity remote code execution flaw
A serious authentication bypass issue affecting TeamCity On-Premises that might be used to accomplish remote code execution is being alerted by JetBrains.
An attacker with HTTPS access to a TeamCity server can use the security flaw, known as CVE-2026-63077, to circumvent authentication through the agent polling protocol and run arbitrary operating system commands with the server process's capabilities.
JetBrains cautions in the advisory that all versions of TeamCity On-Premises are impacted, however TeamCity Cloud users are not obliged to take any action because the needed precautions have already been taken. Software development, testing, and deployment are all done with TeamCity, a commercial continuous integration and continuous delivery (CI/CD) server.
According to Daniel Gal...

