A critical unauthenticated remote code execution (RCE) vulnerability has been identified in TeamCity On-Premises, a widely used continuous integration and delivery system from JetBrains This article explores vulnerability identified teamcity. . This flaw allows attackers with just HTTP(S) access to exploit the service without authentication, enabling them to execute arbitrary operating system commands on behalf of the TeamCity server process.
The vulnerability lies within TeamCity’s agent polling protocol, which agents use to communicate with the central server. As a pivotal component in software build pipelines, this flaw could expose sensitive data and configurations, as well as modify server state and build settings. The issue poses a significant threat to build artifacts and opens up opportunities for poisoning downstream CI/CD pipelines, increasing the risk of broader software supply-chain attacks.
JetBrains published its advisory on July 27, 2026, stating that it does not have evidence of active exploitation at the time of release, though the flaw's unauthenticated nature makes rapid weaponization likely once details are further disseminated.












