JETBRAINS has released patches for a critical vulnerability in TeamCity On-Premises, tracked as CVE-2026-63077, with a CVSS score of 9.8. This vulnerability allows unauthenticated attackers to bypass authentication and execute remote code, potentially compromising TeamCity data, configurations, and CI/CD pipelines. The flaw affects all versions of TeamCity On-Premises. JetBrains has introduced fixes in versions 2025.11.7 and 2026.1.3 and provided a security patch plugin for legacy versions.
Users are urged to update or apply the patch and implement security measures such as limiting access and running servers with minimal privileges.