Skip to content
COOEY

FAIL › dossier

jetbrains

VENDOR

· dossier confidence 20%

JetBrains is a high-risk vendor for DIB/CMMC due to repeated critical RCE vulnerabilities in core products (TeamCity, IntelliJ IDEA) that enable unauthenticated remote code execution and supply-chain compromise.

PROFILE
CategorySoftware VendorWhat they doJetBrains develops and licenses IDEs, CI/CD platforms, and developer tools for enterprise software development. Websitehttps://www.jetbrains.com ↗
SECURITY POSTURE

High-risk vendor with repeated critical RCE vulnerabilities in core products (TeamCity, IntelliJ IDEA) and unpatched path traversal flaws.

Notable failures
  • CVE-2023-42793: TeamCity authentication bypass RCE exploited by ransomware
  • CVE-2024-27198: TeamCity admin action bypass without credentials
  • CVE-2026-59792: IntelliJ IDEA path traversal RCE via workspace ID
  • CVE-2026-63077: TeamCity unauthenticated RCE via agent polling
  • CVE-2026-64815: IntelliJ IDEA arbitrary code injection
Patterns: Repeated critical RCEs in TeamCity and IntelliJ IDEA; Authentication bypasses enabling admin actions without credentials; Path traversal vulnerabilities in project workspace handling
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2023-10-04 CVE-2023-42793 critical JetBrains TeamCity suffered an authentication bypass leading to remote code execution, actively exploited by ransomware actors.
2024-03-07 CVE-2024-27198 critical An authentication bypass in JetBrains TeamCity lets attackers perform admin actions without valid credentials.
2026-08-05 CVE-2026-63077 high JetBrains TeamCity exposed RCE via agent polling protocol
2026-07-10 CVE-2026-59792 critical JetBrains shipped an unpatched path traversal RCE in IntelliJ IDEA that allows remote code execution via project workspace ID handling.
2026-04-20 CVE-2024-27199 critical JetBrains TeamCity exploited via CVE-2024-27199 enables limited admin actions, posing a supply-chain risk for DIB organizations using the service.
2026-07-23 CVE-2026-64815 high CVE-2026-64815: In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible v
2026-07-23 CVE-2026-65906 high CVE-2026-65906: In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL s
2026-07-14 CVE-2026-62422 critical CVE-2026-62422: In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.
Open questions: Impact of unpatched vulnerabilities on active DIB customers · Remediation timeline for CVE-2026-59792 and CVE-2026-64815
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-02 03:44:22.892286+00:00