# TeamCity agent-polling protocol authentication bypass to RCE

Source: https://startwithidentity.com/cves/cve-2026-63077/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

TeamCity On-Premises accepted an unauthenticated request on the agent polling protocol, the channel build agents use to check in. Once past that check, the attacker runs OS commands as the server process. Every on-prem version was in scope. Cloud was not. JetBrains published on 27 July 2026, fixed in 2025.11.7 and 2026.1.3, with a back-ported plugin to 2017.1. We covered the disclosure in [identity news](https://startwithidentity.com/blog/2026-07-27-jetbrains-teamcity-authentication-bypass-rce/).

## Why it matters

This is the third TeamCity authentication bypass in the catalog, after [CVE-2023-42793](https://startwithidentity.com/cves/cve-2023-42793/) and [CVE-2024-27198](https://startwithidentity.com/cves/cve-2024-27198/), both CISA KEV. CI credentials are production identity. An unauthenticated RCE there is a supply-chain foothold.

## What to do

- Patch to 2025.11.7 / 2026.1.3, or confirm the security-patch plugin applied. Do not wait for "no confirmed exploitation."
- Keep TeamCity off the internet. Agent traffic can stay internal.
- If the server was public on 27 July 2026, rotate every credential the pipeline could reach.

## After you patch

Patching closes the entry point. It does not remove access an attacker established through it.

- **Revoke sessions and API tokens** on the affected system rather than only resetting passwords.
- **Audit accounts, tokens, and administrative changes** made during the exposure window.
- **Rotate credentials the system stored or could reach**, including directory service accounts and integration keys. See [secrets rotation](https://startwithidentity.com/glossary/secrets-rotation/).
- **Treat the system as a pivot**: whatever it could authenticate to is in scope until you have checked it.

## Sources

- [NVD: CVE-2026-63077](https://nvd.nist.gov/vuln/detail/CVE-2026-63077)
- [Start with Identity news, 27 July 2026](https://startwithidentity.com/blog/2026-07-27-jetbrains-teamcity-authentication-bypass-rce/)
