DEV Community

Cover image for JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution

Summary

JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines.

Take Action:

If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeover. TeamCity Cloud is already patched and needs no action. If you can't update right away, install the security patch plugin (for versions 2017.1 and later) and restrict access to your TeamCity server to trusted internal networks or a VPN.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)