{"id":16538,"date":"2026-07-31T10:52:26","date_gmt":"2026-07-31T10:52:26","guid":{"rendered":"https:\/\/newestek.com\/?p=16538"},"modified":"2026-07-31T10:52:26","modified_gmt":"2026-07-31T10:52:26","slug":"jetbrains-says-a-crafted-http-request-could-break-teamcity","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16538","title":{"rendered":"JetBrains says a crafted HTTP request could break TeamCity"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">JetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary operating system commands on vulnerable servers.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary commands,\u201c the company said in a security <a href=\"https:\/\/blog.jetbrains.com\/teamcity\/2026\/07\/cve-2026-63077\/\" target=\"_blank\" rel=\"noreferrer noopener\">advisory<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The flaw, tracked as CVE-2026-63077, affects all TeamCity On-Premises deployments and has been fixed in versions 2025.11.7 and 2026.1.3.<\/p>\n<p class=\"wp-block-paragraph\">JetBrains warned that the flaw potentially exposes build environments, stored credentials, and software supply chains. Customers unable to upgrade are advised to deploy a security patch plugin immediately.<\/p>\n<p class=\"wp-block-paragraph\">TeamCity Cloud customers are not required to take any action, the company reassured.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>RCE achieved without authentication<\/h2>\n<p class=\"wp-block-paragraph\">According to JetBrains, the vulnerability resides in the TeamCity agent polling protocol, allowing an attacker with HTTP(S) access to bypass authentication and execute code with the <a href=\"https:\/\/www.csoonline.com\/article\/1312926\/bianlian-group-exploits-teamcity-again-deploys-powershell-backdoor.html\">privileges <\/a>of the TeamCity server process.<\/p>\n<p class=\"wp-block-paragraph\">The vulnerability carries a CVSS score of 9.8 out of 10 as it requires no authentication or user interaction, making internet-exposed TeamCity servers particularly attractive targets. Classified under <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-63077\">CWE-502<\/a> (deserialization of unstructured data), the flaw can be used to send specially crafted data through the affected agent polling protocol to trigger remote code execution (RCE).<\/p>\n<p class=\"wp-block-paragraph\">\u201cDepending on the privileges granted to the TeamCity server process, a successful attack could expose TeamCity data, configurations, and stored credentials, modify server state, and potentially compromise the integrity of build artifacts and downstream CI\/CD pipelines,\u201d the company added.<\/p>\n<p class=\"wp-block-paragraph\">The issue was privately reported on July 10 by security researcher Antoni Tremblay through JetBrains\u2019 coordinated disclosure process.<\/p>\n<p class=\"wp-block-paragraph\">JetBrains said it had found no evidence of active exploitation at the time of publishing the advisory.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Developers have two mitigation paths<\/h2>\n<p class=\"wp-block-paragraph\">JetBrains is recommending that customers upgrade directly to TeamCity 2025.11.7 or 2026.1.3, both of which include a permanent fix for the vulnerability.<\/p>\n<p class=\"wp-block-paragraph\">Organizations unable to upgrade immediately can instead deploy a <a href=\"https:\/\/www.jetbrains.com\/help\/teamcity\/installing-additional-plugins.html\" target=\"_blank\" rel=\"noreferrer noopener\">security patch plugin<\/a>, which is available for TeamCity versions 2017.1 and later. Servers running versions 2017.1 through 2018.1 require a restart after installing the plugin, while newer supported releases can enable the fix without restarting, the company added.<\/p>\n<p class=\"wp-block-paragraph\">The company also advised administrators whose TeamCity servers are publicly accessible to restrict external access if neither mitigation can be applied immediately.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAs a general best practice, we strongly recommend limiting network access to TeamCity servers to trusted networks wherever possible,\u201d the company said. \u201cWe also recommend running the TeamCity server with the minimum operating system privileges required for normal operation.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Given the vulnerability\u2019s pre-authentication nature and the <a href=\"https:\/\/www.csoonline.com\/article\/1312183\/teamcity-supply-chain-bugs-receive-massive-exploitation.html\">history<\/a> of threat actors rapidly weaponizing TeamCity flaws, organizations running self-hosted CI\/CD infrastructure are advised to prioritize emergency patching over routine maintenance windows.<\/p>\n<p class=\"wp-block-paragraph\">The advisory also recommended running TeamCity servers on dedicated hosts separate from build agents, as per official <a href=\"https:\/\/www.jetbrains.com\/help\/teamcity\/install-and-start-teamcity-agents.html\" target=\"_blank\" rel=\"noreferrer noopener\">instructions<\/a>.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>JetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary operating system commands on vulnerable servers. \u201cIf exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary commands,\u201c the company said in a security advisory. The flaw, tracked as CVE-2026-63077, affects all&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16538\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16538","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16538"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16538\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}