FAIL › dossier
jetbrains
VENDOR· dossier confidence 20%
JetBrains is a high-risk vendor for DIB/CMMC due to repeated critical RCE vulnerabilities in core products (TeamCity, IntelliJ IDEA) that enable unauthenticated remote code execution and supply-chain compromise.
PROFILE
CategorySoftware VendorWhat they doJetBrains develops and licenses IDEs, CI/CD platforms, and developer tools for enterprise software development.
Websitehttps://www.jetbrains.com ↗
SECURITY POSTURE
High-risk vendor with repeated critical RCE vulnerabilities in core products (TeamCity, IntelliJ IDEA) and unpatched path traversal flaws.
Notable failures
- CVE-2023-42793: TeamCity authentication bypass RCE exploited by ransomware
- CVE-2024-27198: TeamCity admin action bypass without credentials
- CVE-2026-59792: IntelliJ IDEA path traversal RCE via workspace ID
- CVE-2026-63077: TeamCity unauthenticated RCE via agent polling
- CVE-2026-64815: IntelliJ IDEA arbitrary code injection
Patterns: Repeated critical RCEs in TeamCity and IntelliJ IDEA; Authentication bypasses enabling admin actions without credentials; Path traversal vulnerabilities in project workspace handling
FAILURE HISTORY · 8
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2023-10-04 | CVE-2023-42793 | critical | JetBrains TeamCity suffered an authentication bypass leading to remote code execution, actively exploited by ransomware actors. |
| 2024-03-07 | CVE-2024-27198 | critical | An authentication bypass in JetBrains TeamCity lets attackers perform admin actions without valid credentials. |
| 2026-08-05 | CVE-2026-63077 | high | JetBrains TeamCity exposed RCE via agent polling protocol |
| 2026-07-10 | CVE-2026-59792 | critical | JetBrains shipped an unpatched path traversal RCE in IntelliJ IDEA that allows remote code execution via project workspace ID handling. |
| 2026-04-20 | CVE-2024-27199 | critical | JetBrains TeamCity exploited via CVE-2024-27199 enables limited admin actions, posing a supply-chain risk for DIB organizations using the service. |
| 2026-07-23 | CVE-2026-64815 | high | CVE-2026-64815: In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible v |
| 2026-07-23 | CVE-2026-65906 | high | CVE-2026-65906: In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL s |
| 2026-07-14 | CVE-2026-62422 | critical | CVE-2026-62422: In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1. |
DOSSIER SOURCES
- Jetbrains CVEs and Security Vulnerabilities - OpenCVE · app.opencve.io
- TeamCity RCE Vulnerability: Critical Authentication Bypass · cybernexoranews.substack.com
- CVE-2026-63077, TeamCity Unauthenticated RCE and CI/CD Supply Chain Risk · www.penligent.ai
Open questions: Impact of unpatched vulnerabilities on active DIB customers · Remediation timeline for CVE-2026-59792 and CVE-2026-64815
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-02 03:44:22.892286+00:00