# JetBrains TeamCity 2024 authentication bypass, admin access

Source: https://startwithidentity.com/cves/cve-2024-27198/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

TeamCity On-Premises accepted an unauthenticated request that became an administrator session. CVSS 9.8. Published 4 March 2024. Public estimates at the time put a large share of internet-facing instances in the exploited set. CISA added it to KEV. Cloud was not affected.

## Why it matters

CI is an identity plane: cloud keys, signing certs, deployment tokens. TeamCity's 2023 bypass ([CVE-2023-42793](https://startwithidentity.com/cves/cve-2023-42793/)) was already a nation-state and ransomware favorite. The 2024 ID is the same product failing the same test. Our [July 2026 TeamCity note](https://startwithidentity.com/blog/2026-07-27-jetbrains-teamcity-authentication-bypass-rce/) (CVE-2026-63077) exists because this pattern did not stop.

## What to do

- Patch to the March 2024 TeamCity build. If the server was public in early March 2024, rotate every credential the build system could reach.
- Review newly created admin users and SSH keys on agents.
- Do not put TeamCity on the internet. Agent traffic can stay internal.

## After you patch

A build system holds the credentials to ship your software, so an unauthenticated bypass here is a [software supply chain](https://startwithidentity.com/glossary/secrets-management/) event rather than one compromised host.

- **Rotate every secret the server held**: signing keys, registry and cloud credentials, deploy tokens, and any [service account](https://startwithidentity.com/glossary/service-account/) it authenticated as.
- **Review build history for injected steps** during the exposure window, and compare published artifacts against expected hashes.
- **Revoke sessions and administrative tokens** rather than only resetting passwords.
- **Check for accounts and API tokens created during the window**, which is the standard persistence step after this class of bypass.

## Sources

- [NVD: CVE-2024-27198](https://nvd.nist.gov/vuln/detail/CVE-2024-27198)
- CISA KEV
- JetBrains TeamCity advisory, March 2024
