JetBrains says a critical security vulnerability has been found in TeamCity On-Premises that could allow an unauthenticated attacker to bypass authentication and execute arbitrary operating system commands. The issue is tracked as CVE-2026-63077 and has a CVSS score of 9.8, indicating a high risk. JetBrains states that the flaw affects all TeamCity On-Premises versions and can be exploited by an attacker who has HTTP(S) access to a TeamCity server. If successfully exploited, the commands run with the privileges of the TeamCity server process.

To address the vulnerability, JetBrains urges customers to update to the fixed releases: TeamCity 2025.11.7 or TeamCity 2026.1.3. In addition, JetBrains reports that these maintenance updates also address more than 20 security vulnerabilities in each release, with 2026.1.3 also resolving several functional issues. JetBrains indicates that TeamCity Cloud instances have already been handled, while the focus of the advisory is on updating self-hosted installations to the specified patched versions.