Identity CVE · Other
CVE-2026-63077TeamCity agent-polling protocol authentication bypass to RCE
critical
What broke
TeamCity On-Premises accepted an unauthenticated request on the agent polling protocol, the channel build agents use to check in. Once past that check, the attacker runs OS commands as the server process. Every on-prem version was in scope. Cloud was not. JetBrains published on 27 July 2026, fixed in 2025.11.7 and 2026.1.3, with a back-ported plugin to 2017.1. We covered the disclosure in identity news.
Why it matters
This is the third TeamCity authentication bypass in the catalog, after CVE-2023-42793 and CVE-2024-27198, both CISA KEV. CI credentials are production identity. An unauthenticated RCE there is a supply-chain foothold.
What to do
- Patch to 2025.11.7 / 2026.1.3, or confirm the security-patch plugin applied. Do not wait for "no confirmed exploitation."
- Keep TeamCity off the internet. Agent traffic can stay internal.
- If the server was public on 27 July 2026, rotate every credential the pipeline could reach.
Sources
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.