Skip to content
COOEY

FAIL › dossier

TeamCity

PRODUCT

· dossier confidence 20%

PROFILE
CategoryCI/CDWhat they doJetBrains TeamCity is a popular CI/CD server that automates the software build, test, and deployment processes. Websitehttps://www.jetbrains.com/teamcity/ ↗
SECURITY POSTURE

JetBrains has faced multiple critical vulnerabilities in TeamCity, indicating potential weaknesses in its security posture.

Notable failures
  • CVE-2023-42793: Authentic bypass leading to remote code execution
  • CVE-2024-27198: Authentic bypass allowing admin actions without credentials
  • CVE-2026-63077: Unauthenticated RCE via agent polling protocol
  • CVE-2024-27199: Limited admin actions enabled by a vulnerability
Patterns: Repeated unpatched vulnerabilities affecting remote code execution; Lack of proper authentication controls leading to privilege escalation
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2023-10-04 CVE-2023-42793 critical JetBrains TeamCity suffered an authentication bypass leading to remote code execution, actively exploited by ransomware actors.
2024-03-07 CVE-2024-27198 critical An authentication bypass in JetBrains TeamCity lets attackers perform admin actions without valid credentials.
2026-08-05 CVE-2026-63077 high JetBrains TeamCity exposed RCE via agent polling protocol
2026-04-20 CVE-2024-27199 critical JetBrains TeamCity exploited via CVE-2024-27199 enables limited admin actions, posing a supply-chain risk for DIB organizations using the service.
2026-07-23 CVE-2026-65906 high CVE-2026-65906: In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL s
Open questions: How has the company addressed the identified security issues? · What measures have been implemented to prevent future vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-06 03:43:03.484148+00:00