www.rapid7.com 8/7/2026, 6:52:03 PM · external

Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)

Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
Developing story incident 16 articles tracked
JetBrains TeamCity unauthenticated remote code execution flaw (CVE-2026-63077)
CyberSIXT Evidence Panel
Primary Source blog.jetbrains.com
CISA KEV Listed in KEV
Patch Patch Available

RAPID 7's analysis reveals a critical unauthenticated remote code execution vulnerability (CVE-2026-63077) in JetBrains TeamCity, disclosed on July 27, 2026. An attacker can exploit this vulnerability over HTTP or HTTPS, allowing them to execute commands with the same privileges as the TeamCity server process. JetBrains initially reported no known active exploitation, but CISA later added it to their Known Exploited Vulnerabilities catalog after confirming exploitation in the wild.

The vulnerability stems from an unsafe deserialization issue due to TeamCity's incorrect handling of XStream permissions in version 2026.1.2. A patch in version 2026.1.3 addressed this by clearing default permissions for deserialization. The analysis includes details of how exploitation occurs via unauthorized XML requests, creating a gadget chain leading to command execution. A proof-of-concept script is available, demonstrating the exploitation process. Organizations are advised to apply the patch to remediate the vulnerability.

View Primary Source Via www.rapid7.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline