DevSecOps

CVE-2026-63077: Critical TeamCity Vulnerability Enables Remote Code Execution

JetBrains released an emergency patch for TeamCity On-Premises after researchers discovered an authentication vulnerability that allows an unauthenticated attacker to execute arbitrary code on the build server.

The flaw, tracked as CVE-2026-63077, affects TeamCity versions prior to 2026.03.1 and resides in how the remote administration endpoint handles session tokens. An attacker sending a specially crafted request can bypass authentication checks and obtain server administrator privileges.

Because TeamCity is commonly integrated into CI/CD pipelines with access to deployment secrets, source repositories, and infrastructure credentials, exploitation of this flaw represents a direct software supply-chain compromise risk.

Organizations are advised to patch immediately, or at minimum restrict network access to the TeamCity admin panel to trusted IPs until the patch can be applied.