hacker-news · Crawled Jul 28, 2026

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

Read original article ↗

AI Summary

A critical vulnerability in JetBrains TeamCity On-Premises, tracked as CVE-2026-63077, allows unauthenticated attackers to execute arbitrary operating system commands via the agent polling protocol. The flaw enables authentication bypass over HTTP(S), potentially leading to full server compromise, data exposure, and credential theft. JetBrains has released patches and updated versions to address the issue, but no known in-the-wild exploitation has been observed yet.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.