Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-25 ยท updated: 2026-08-25 ยท tags: [cve, jetbrains, teamcity, auth-bypass, rce, ci-cd, actively-exploited, critical] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, devops, software-development] ยท au_impact: true

CVE-2026-63077

CVE-2026-63077 is a critical authentication-bypass vulnerability (CVSS 9.8) affecting all versions of JetBrains TeamCity On-Premises. ASD's Australian Cyber Security Centre (ACSC) has observed active exploitation within Australia: an unauthenticated attacker with HTTP(S) access can bypass authentication checks and execute arbitrary operating-system commands on the CI/CD server.

Vulnerability Details

Attribute Detail
CVE CVE-2026-63077
Product JetBrains TeamCity On-Premises (all versions)
CVSS 9.8 (Critical)
Type Unauthenticated authentication bypass โ†’ OS command execution
Precondition HTTP(S) network access to the server
Exploitation Actively exploited within Australia (ACSC alert, 2026-08-24)

Australian Context

The ACSC alert reports no specific industry or sector being targeted. TeamCity frequently sits in small development shops rather than enterprise SOCs, so the alert carries an SMB audience tag. Compromise of a TeamCity server can expose source code, build artifacts, deployment credentials and downstream production environments.

Mitigation

  1. Review environments for vulnerable TeamCity On-Premises servers and question whether build interfaces need internet exposure at all
  2. Apply vendor mitigations and hunt using the vendor IoCs provided with the alert
  3. Check third-party and MSP-managed instances โ€” the alert explicitly asks organisations to confirm their providers have patched and are monitoring

Source

Related