vulnerability
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Critical
Summary
JetBrains has identified and patched a critical vulnerability in TeamCity On-Premises, allowing unauthenticated attackers to execute OS commands. This flaw, assigned CVE-2026-63077, could lead to data exposure and server modification if not addressed immediately. The vulnerability has been resolved with updated versions and a security patch plugin for older versions.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
