criticalZero-Day

JetBrains TeamCity On-Premises Authentication Bypass RCE

First seen Jul 31, 2026 · Updated Jul 31, 2026 · CVSS 9.8

teamcityauthentication-bypassrceci-cdsupply-chain-riskagent-relevant

JetBrains disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that can be chained to achieve remote code execution. Given TeamCity's role as a CI/CD server, successful exploitation could allow attackers to compromise build pipelines, inject malicious code, and pivot into connected infrastructure. Organizations running affected instances should patch immediately given the high likelihood of active exploitation attempts.

Technical Analysis

The vulnerability allows an unauthenticated attacker to bypass authentication controls on TeamCity On-Premises servers, subsequently leveraging administrative functionality to execute arbitrary code on the host. As a CI/CD platform, TeamCity servers typically hold sensitive credentials, API keys, and deployment secrets, making this an attractive high-value target for both opportunistic and targeted attackers, including ransomware affiliates and nation-state actors who have historically abused prior TeamCity flaws (e.g., CVE-2023-42793) for initial access and supply-chain attacks. No CVE identifier was specified in the source reporting, though JetBrains has released a patched version. Organizations that use TeamCity to build, test, or deploy AI agent frameworks, LLM tool integrations, or RAG pipelines are at risk of having build artifacts tampered with or credentials (including LLM API keys and vector database secrets) exfiltrated, which could propagate compromised code or leaked secrets directly into production agent systems.

Affected Systems

JetBrains TeamCity On-Premises (self-hosted installations); specific vulnerable version range not detailed in source reporting — organizations should consult JetBrains' official advisory for exact affected versions and confirm patch level.

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) disclosed in source reporting at time of publication.

Remediation Steps

  1. 1

    Apply official patch

    Upgrade TeamCity On-Premises to the latest patched version released by JetBrains immediately.

  2. 2

    Restrict network exposure

    Ensure TeamCity server admin interfaces are not exposed directly to the internet; restrict access via VPN or IP allowlisting.

  3. 3

    Audit authentication logs

    Review server logs for unusual authentication attempts, unexpected admin actions, or unauthorized plugin installations.

  4. 4

    Rotate credentials

    Rotate all secrets, API keys, and credentials stored in or accessible via TeamCity, including any keys used by connected AI agent or LLM tooling.

  5. 5

    Review build artifacts

    Audit recent build outputs and deployment pipelines for signs of tampering or injected malicious code.

Industries Most Exposed

Software DevelopmentTechnologyFinancial ServicesGovernmentHealthcareAny organization using CI/CD pipelines

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.