Vulnerability record · CVE-2023-42793 · published 19 September 2023
CVE-2023-42793: JetBrains TeamCity authentication bypass leads to remote code execution
Jetbrains · Teamcity
JetBrains TeamCity before 2023.05.4 contains an authentication bypass via an alternate path, classified as CWE-288 and CWE-306, that allows an unauthenticated attacker to reach a critical function and achieve remote code execution on the TeamCity Server. Because TeamCity is a CI/CD server, compromise can expose build pipelines, credentials and deployment paths.
Description
In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network RCE, CISA KEV listing with known ransomware use, and near-maximum EPSS probability make this an urgent patching priority.
What it is
JetBrains TeamCity before 2023.05.4 contains an authentication bypass via an alternate path, classified as CWE-288 and CWE-306, that allows an unauthenticated attacker to reach a critical function and achieve remote code execution on the TeamCity Server. Because TeamCity is a CI/CD server, compromise can expose build pipelines, credentials and deployment paths.
Impact
An unauthenticated attacker can bypass authentication and execute code on the TeamCity Server, gaining control of the CI/CD system. This can lead to theft of source code and secrets, tampering with builds, and lateral movement into connected environments.
Attack surface
The vulnerability is network-reachable (CVSS vector AV:N) with no privileges or user interaction required (PR:N, UI:N), so any host that can reach the TeamCity Server web interface can attempt it. No authentication is needed.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2023-10-04 with a due date of 2023-10-25 and flags known ransomware campaign use, and EPSS shows a 30-day probability of 0.99979 (percentile 0.9998). Public exploit references are tagged Exploit, confirming active exploitation.
What to do
- Upgrade JetBrains TeamCity to 2023.05.4 or later immediately.
- If immediate upgrade is not possible, apply the vendor's recommended mitigations or discontinue use of the product as directed by CISA.
- Restrict network access to the TeamCity Server web interface to trusted management networks only.
- Rotate credentials, tokens and secrets stored in or accessible from TeamCity after patching.
- Review CI/CD build configurations and deployment credentials for signs of tampering.
Detection
- Monitor TeamCity server logs for authentication bypass attempts or unexpected administrative actions.
- Hunt for unexpected processes, scripts or network connections spawned by the TeamCity Server process.
- Review CI/CD pipeline changes and new build steps for unauthorized modifications.
- Alert on access to TeamCity management endpoints from untrusted or external IP addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-42793 to the Known Exploited Vulnerabilities catalog on 4 October 2023 as "JetBrains TeamCity Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 25 October 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-42793 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-42793), CISA KEV, FIRST EPSS (scores of 2026-09-20). This page is refreshed as NVD updates the record.