TeamCity Vulnerability Shows Why CI/CD Environments Must Be Treated as Critical Infrastructure
Overview
JetBrains published an advisory for a critical vulnerability in TeamCity On-Premises, tracked as CVE-2026-63077. The vulnerability affects all locally installed TeamCity versions and may allow command execution on the server without prior login.
TeamCity Cloud has already been updated by JetBrains. For on-premises installations, fixes are available in versions 2025.11.7 and 2026.1.3. For older environments, JetBrains also provides a security patch plugin for versions 2017.1 and newer, although a full upgrade to the latest version is recommended.
The topic matters because TeamCity is not an ordinary server. It often manages software build, test and delivery processes. If such an environment is compromised, the risk can extend to code, build processes, configurations, service accounts and stored credentials.
What Happened
CVE-2026-63077 may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute operating system commands with the privileges of the TeamCity server process.
According to JetBrains, the vulnerability is related to the agent polling protocol. If successfully exploited, an attacker may execute commands based on the privileges assigned to the TeamCity server process.
At the time of publication, JetBrains stated that there is no evidence of active exploitation. The risk is still high because the vulnerability affects all TeamCity On-Premises versions and may be used against servers reachable over HTTP(S).
Why This Matters
CI/CD (Continuous Integration/Continuous Delivery) environments are part of the software trust chain. They often have access to source code, build artifacts, deployment keys, environment variables, secrets, package repositories and internal systems.
A compromised TeamCity server may create risk for:
- source code;
- build and delivery processes;
- stored credentials and tokens;
- deployment configurations;
- software supply chain integrity;
- trust in published artifacts;
- downstream systems and customers.
This is why CI/CD environments should be treated as critical infrastructure, not as secondary development tooling.
Where the Risk Is for Organizations
Organizations are most exposed when they use TeamCity On-Premises and expose the login screen, REST API or other TeamCity interfaces to the internet or a broader internal network.
JetBrains specifically warns that even exposing the TeamCity login screen or REST API can provide attackers with an entry point when newly disclosed vulnerabilities appear.
The risk increases if the TeamCity process runs with overly broad privileges, if stored credentials are not limited, or if the build server has direct access to production environments.
What Should Be Checked
For organizations, the practical review is clear:
- do you use TeamCity On-Premises;
- are servers updated to 2025.11.7 or 2026.1.3;
- has the security patch plugin been applied if a full upgrade is not immediately possible;
- is TeamCity reachable from the internet;
- is there an additional protection layer such as VPN or restricted access;
- which credentials, tokens and deployment permissions are stored in TeamCity.
The main takeaway is practical: if a CI/CD server is externally reachable, it should be treated as a high-risk asset and updated with priority.
DIAMATIX Perspective
This case shows why protecting CI/CD environments is part of protecting the business, not only the responsibility of development teams.
DIAMATIX treats vulnerabilities like this as software supply chain risk. When a build server has access to code, tokens and deployment processes, its compromise may affect more than one system.
Visibility into access, commands, configuration changes and unusual behavior in CI/CD environments should therefore be part of SOC (Security Operations Center) and MDR (Managed Detection and Response) processes.
CISO Analysis
For CISOs, the key question is whether CI/CD environments are included in the real risk management model.
Key questions to review:
- Which TeamCity servers do we use and where are they reachable?
- Do they have access to production credentials or deployment keys?
- Is external access to TeamCity restricted?
- Are all on-premises installations updated?
- Do we monitor commands, changes and unusual activity on build servers?
- Do we have a plan if a CI/CD server is compromised?
The practical takeaway: CI/CD systems must be protected as a critical part of the software chain because code, trust and access to production environments pass through them.
Check whether your CI/CD environments are protected as critical infrastructure
DIAMATIX can help review access, configurations, stored credentials and visibility across build and deployment processes.
Request a CI/CD risk review with DIAMATIX.
Trusted · Innovative · Vigilant
Sources
- JetBrains. Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077).
- JetBrains. TeamCity 2026.1.3 and 2025.11.7 Are Now Available.
- The Hacker News. Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In.
This article is based on publicly available information as of July 2026.






