CI/CD Security Alert: JetBrains Patches Critical TeamCity RCE Flaw CVE-2026-63077

🛡️ Verified Threat IntelDigitalSpying Research Desk
📅 August 3, 2026⏱️ 5 min read

JetBrains has issued an urgent security bulletin warning enterprise organizations of an actively targeted, unauthenticated Remote Code Execution (RCE) vulnerability in on-premises TeamCity Continuous Integration and Continuous Deployment (CI/CD) servers. Tracked as CVE-2026-63077 with a CVSS v3.1 rating of 9.8 (Critical), the vulnerability enables remote threat actors to bypass authentication filters, execute arbitrary system commands, and poison software release artifacts before distribution.

The Strategic High Ground of CI/CD Infrastructure

In modern software engineering ecosystems, CI/CD orchestration servers occupy the ultimate trust boundary. TeamCity servers store enterprise source code, maintain persistent connections to production Kubernetes clusters, manage privileged deployment cloud keys, and house cryptographic code-signing certificates. Breaching a central build server grants an adversary immediate root-level access to the entirety of an enterprise's software supply chain.

CVE-2026-63077 directly targets this critical nexus. Unlike edge-device flaws that require subsequent network pivoting, compromising a CI/CD controller provides immediate lateral visibility into internal source repositories, build scripts, and production environments across on-premises and multi-cloud infrastructure.

Critical Patch Advisory: Immediate Exploit Risk

Public exploit attempts have been observed scanning for exposed TeamCity web portals. Threat actors are chaining CVE-2026-63077 with automated token generation routines to establish permanent administrative backdoors within seconds of initial port exposure.

Root Cause Analysis: Path Traversal and Controller Deserialization

The technical vulnerability resides inside TeamCity's underlying Spring Web MVC dispatch framework and custom authentication interceptors. TeamCity enforces administrative authorization through a filter chain that inspects requested URI paths against a list of protected routes.

Under CVE-2026-63077, improper canonical path normalization in the custom filter chain allows an unauthenticated request to traverse security boundaries. By appending specially formatted matrix parameters or URI path segments (e.g., /app/rest/users;bypass/adminToken), an attacker causes the authentication filter to treat the request as a public asset path, while the underlying Spring servlet dispatcher forwards the payload directly to privileged controller handlers.

  1. Filter Chain Confusion: An unauthenticated attacker sends an HTTP POST request targeting an internal administrative controller via path normalization confusion. The authentication filter evaluates the URL string before path normalization and allows the request through.
  2. Internal Controller Invocation: When the request reaches the TeamCity Spring context, the internal dispatcher resolves the normalized path to an administrative diagnostic endpoint designed for maintenance operations.
  3. Administrative Credential Injection: Exploiting the exposed endpoint, the attacker invokes internal user creation routines, generating a new TeamCity user account equipped with the SYSTEM_ADMIN global role.
  4. Arbitrary Process Spawning: Armed with administrator API tokens, the attacker invokes TeamCity's programmatic agent management or diagnostic shell APIs, executing arbitrary bash or PowerShell scripts with the operating system privileges of the underlying TeamCity service account.
# Threat Actor Exploitation Pattern (Reconstructed HTTP Sequence)
POST /app/rest/users;bypass/admin/generateToken HTTP/1.1
Host: build.target-enterprise.internal
User-Agent: Mozilla/5.0 (Security-Audit-Research)
Content-Type: application/json
Content-Length: 78

{"username": "build_daemon_svc", "roles": ["SYSTEM_ADMIN"], "description": "telemetry"}
Vulnerability Metric Observed Telemetry Detail Operational Severity
CVE Identifier CVE-2026-63077 (TeamCity Controller Bypass) Critical (CVSS 9.8)
Attack Vector Network / HTTP Ingress (Port 8111 or 443) Unauthenticated Remote Arbitrary Code Execution
Vulnerable Components TeamCity Server on-premises versions prior to 2026.07.2 Complete CI/CD Infrastructure Compromise
Threat Actor Objective Software Supply-Chain Tampering & Secret Theft Code Injection & Lateral Cloud Pivoting

Forensic Investigation and Threat Hunting Workflow

Incident response teams with on-premises TeamCity deployments must immediately perform forensic audits of access logs and host operating system process trees. Threat actors exploiting CVE-2026-63077 leave distinct forensic artifacts:

1. HTTP Access Log Forensics: Inspect teamcity-server.log and Tomcat access logs (catalina.out) for requests containing semicolons (;), dot-dot-slash sequences (..;/), or unexpected calls to /app/rest/users originating from external IP addresses without prior session authentication.

2. User Database Auditing: Inspect the internal TeamCity database (PostgreSQL, MySQL, or internal HSQLDB) for newly created administrator accounts. Cross-reference account creation timestamps against user management audit logs. Malicious actors frequently name accounts deceptively (e.g., buildadmin, svc_agent, or teamcity_sync).

3. Child Process Telemetry: Monitor endpoint telemetry for anomalous process execution trees where the parent process is Java (java.exe on Windows or java on Linux). Legitimate build agents spawn compilation tools (such as mvn, gradle, or docker); however, invocations of cmd.exe /c, powershell.exe -enc, curl, wget, or nc directly from the server parent process indicate active intrusion.

# Hunting Malicious Process Spawns on Linux TeamCity Hosts via auditd
ausearch -i -m EXECVE -c java | grep -E "(bash|sh|curl|wget|nc|python)"

Sigma Detection Rule for SIEM and SOC Deployment

To detect ongoing exploitation across web application firewalls and proxy logs, security operations teams should deploy the following standardized Sigma detection rule:

title: JetBrains TeamCity Authentication Bypass CVE-2026-63077
status: critical
description: Detects exploitation attempts against TeamCity web controllers using URI matrix parameters
logsource:
    category: webserver
detection:
    selection_uri:
        cs-uri-stem|contains:
            - '/app/rest/users;'
            - '/admin/diagnostic.jsp;'
            - ';bypass/'
    selection_method:
        cs-method:
            - 'POST'
            - 'PUT'
    condition: selection_uri and selection_method
falsepositives:
    - None observed in production
level: critical

Remediation Protocols and Supply Chain Incident Containment

If an enterprise suspects or confirms exploitation of CVE-2026-63077, simple server patching is insufficient due to the risk of persistent supply-chain contamination. Security teams must execute a four-phase containment runbook:

  • Isolate and Apply Patches: Immediately restrict network access to the TeamCity web interface to internal VPN subnets. Apply JetBrains official security updates (version 2026.07.2 or later) or deploy the official JetBrains security patch plugin.
  • Revoke and Rotate All CI/CD Secrets: Treat all credentials stored in TeamCity build configurations, environment parameters, and secure values as fully compromised. Immediately rotate all AWS/GCP/Azure access keys, Kubernetes cluster tokens, database connection strings, and third-party SaaS API keys.
  • Re-Key Code Signing Infrastructure: Revoke and re-issue any code-signing certificates stored or accessible on the TeamCity build server or build agents. Verify cryptographic signatures on all software binaries released during the exposure window.
  • Audit Git Repository Commits: Inspect git history across all projects built by the compromised server during the window of vulnerability. Ensure that no automated commits, malicious dependencies, or stealthy backdoors were injected into production source trees.
  • Network Ingress Hardening: Never expose on-premises CI/CD administrative portals directly to the public internet. Front build infrastructure with identity-aware proxies requiring hardware-bound MFA (FIDO2) and enforce strict WAF rules blocking path-traversal delimiters.
Classification:Cyber Security IntelligenceZero-Day AnalysisDefensive Engineering
🛡️

About the DigitalSpying Research Desk

The DigitalSpying Threat Intelligence Desk is composed of seasoned security researchers, reverse engineers, and blue team architects. Our mission is to publish reproducible, peer-audited threat analyses, hardware security evaluations, and defensive countermeasures.