
PEACH
Un cadre d’isolation des locataires
CVE-2026-63077 is a critical unauthenticated remote code execution (RCE) vulnerability in JetBrains TeamCity, exploitable via the agent polling protocol without any authentication. It affects TeamCity versions before 2026.1.3 and before 2025.11.7. The vulnerability was disclosed on July 27, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, JetBrains Blog).
The root cause is improper deserialization of untrusted data (CWE-502) within TeamCity's agent polling protocol, which is used by build agents to communicate with the TeamCity server. An unauthenticated remote attacker can send a crafted payload to this protocol endpoint, triggering unsafe deserialization that results in arbitrary code execution on the server. No privileges or user interaction are required, and the attack complexity is low, making it trivially automatable. The vulnerability is mapped to CAPEC-586 (Object Injection) (GitHub Advisory, JetBrains Blog).
Successful exploitation grants an unauthenticated attacker full remote code execution on the TeamCity server, resulting in complete compromise of confidentiality, integrity, and availability. Because TeamCity is a CI/CD platform, a compromised server could expose source code, build secrets, deployment credentials, and pipeline configurations — creating significant supply chain risk. Attackers could leverage access for lateral movement into connected infrastructure, inject malicious code into build artifacts, or disrupt development operations entirely (GitHub Advisory, Security Affairs, Undercode News).
cmd.exe, powershell.exe, /bin/bash, curl, wget); unexpected network connections initiated by the TeamCity service account.JetBrains has released patched versions: TeamCity 2026.1.3 and TeamCity 2025.11.7. All users should upgrade to one of these versions immediately. As a temporary workaround if immediate patching is not possible, implement network segmentation to restrict access to the agent polling protocol endpoint to only trusted build agent IP addresses. JetBrains Cloud-hosted TeamCity instances are not affected (JetBrains Blog, GitHub Advisory).
JetBrains published a dedicated blog post and security advisory on July 27, 2026, urging customers to patch immediately (JetBrains Blog). The vulnerability received broad coverage from security media including The Hacker News, Help Net Security, Security Affairs, GBHackers, and Cyberpress, with many outlets highlighting the supply chain risk posed by a compromised CI/CD server (The Hacker News, Help Net Security, Security Affairs). Community discussion on Reddit and Mastodon reflected urgency given TeamCity's history of high-profile RCE vulnerabilities being rapidly weaponized. Security researchers on social media noted the vulnerability's similarity to prior TeamCity deserialization issues and emphasized the importance of prompt patching.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."