JetBrains has patched a high-severity vulnerability in TeamCity On-Premises, tracked as CVE-2026-44413, that can allow privilege escalation and expose parts of the TeamCity server API to unauthorized users. The company said affected deployments include TeamCity On-Premises 2025.11.4 and earlier, and advised customers to upgrade to TeamCity 2026.1 or apply the available security patch plugin. According to JetBrains, the flaw could expose sensitive data including API tokens, Git credentials, build secrets, logs, and user information, with higher risk in environments that permit inbound connections on non-standard ports or run build agents on the same host as the TeamCity server.
The issue requires access to a TeamCity account, which attackers could obtain through brute force, credential stuffing, leaked credentials, social engineering, or enabled guest access, raising the prospect of follow-on compromise of cloud infrastructure, source code repositories, and software delivery pipelines. The disclosure comes against a backdrop of repeated TeamCity security incidents, including CVE-2024-27198 and CVE-2024-27199, two critical flaws that allowed unauthenticated attackers to bypass authentication, take over servers, alter certificates and ports, and create supply-chain attack paths; those earlier bugs were fixed in 2023.11.4 after researchers warned they could lead to full server compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
JetBrains patched high-severity TeamCity vulnerability CVE-2026-44413 and urged customers using on-premises or self-managed deployments to upgrade to TeamCity 2026.1 or apply the security patch plugin. The flaw can enable privilege escalation and expose parts of the TeamCity server API, potentially revealing secrets such as API tokens, Git credentials, build secrets, logs, and user information.
JetBrains disclosed CVE-2024-27198 and CVE-2024-27199 and released TeamCity On-Premises version 2023.11.4 to fix them, noting TeamCity Cloud had already been patched. The flaws could let unauthenticated attackers bypass authentication and, in the case of CVE-2024-27198, potentially fully compromise servers.
Rapid7 reported the TeamCity On-Premises vulnerabilities later assigned CVE-2024-27198 and CVE-2024-27199 to JetBrains on 2024-02-20. The issues affected all on-premises versions through 2023.11.3.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.