CRITICAL

CVE-2026-63077

Jetbrains Teamcity 2026-07-27 CVSS v3.1
CVSS
9.8
KEV

Description

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Summary dbcve.org

A critical unauthenticated remote code execution vulnerability exists in JetBrains TeamCity's agent polling protocol. Attackers can execute arbitrary code on the TeamCity server without any authentication by sending specially crafted requests through the agent communication channel, which lacks proper input validation.

Mitigation

Immediately upgrade TeamCity to version 2026.1.3 or 2025.11.7 or later. If immediate upgrade is not possible, consider blocking external access to the agent polling endpoints at the network perimeter while planning the upgrade.

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

86.52%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE