← Vulnerability feed

Vulnerability record · CVE-2023-42793 · published 19 September 2023

CVE-2023-42793: JetBrains TeamCity authentication bypass leads to remote code execution

Jetbrains · Teamcity

JetBrains TeamCity before 2023.05.4 contains an authentication bypass via an alternate path, classified as CWE-288 and CWE-306, that allows an unauthenticated attacker to reach a critical function and achieve remote code execution on the TeamCity Server. Because TeamCity is a CI/CD server, compromise can expose build pipelines, credentials and deployment paths.

9.8 CVSS 3.1 Critical CISA KEV since 4 Oct 2023 Known ransomware use EPSS 100% · top 0.1% CWE-288 · Authentication bypass via alternate pathCWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
14References, 3 tagged exploit
17 Jun 2026Last modified by NVD

Description

In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network RCE, CISA KEV listing with known ransomware use, and near-maximum EPSS probability make this an urgent patching priority.

What it is

JetBrains TeamCity before 2023.05.4 contains an authentication bypass via an alternate path, classified as CWE-288 and CWE-306, that allows an unauthenticated attacker to reach a critical function and achieve remote code execution on the TeamCity Server. Because TeamCity is a CI/CD server, compromise can expose build pipelines, credentials and deployment paths.

Impact

An unauthenticated attacker can bypass authentication and execute code on the TeamCity Server, gaining control of the CI/CD system. This can lead to theft of source code and secrets, tampering with builds, and lateral movement into connected environments.

Attack surface

The vulnerability is network-reachable (CVSS vector AV:N) with no privileges or user interaction required (PR:N, UI:N), so any host that can reach the TeamCity Server web interface can attempt it. No authentication is needed.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2023-10-04 with a due date of 2023-10-25 and flags known ransomware campaign use, and EPSS shows a 30-day probability of 0.99979 (percentile 0.9998). Public exploit references are tagged Exploit, confirming active exploitation.

What to do

  • Upgrade JetBrains TeamCity to 2023.05.4 or later immediately.
  • If immediate upgrade is not possible, apply the vendor's recommended mitigations or discontinue use of the product as directed by CISA.
  • Restrict network access to the TeamCity Server web interface to trusted management networks only.
  • Rotate credentials, tokens and secrets stored in or accessible from TeamCity after patching.
  • Review CI/CD build configurations and deployment credentials for signs of tampering.

Detection

  • Monitor TeamCity server logs for authentication bypass attempts or unexpected administrative actions.
  • Hunt for unexpected processes, scripts or network connections spawned by the TeamCity Server process.
  • Review CI/CD pipeline changes and new build steps for unauthorized modifications.
  • Alert on access to TeamCity management endpoints from untrusted or external IP addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-42793 to the Known Exploited Vulnerabilities catalog on 4 October 2023 as "JetBrains TeamCity Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 25 October 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/174860/JetBrains-TeamCity-Unauthenticated-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793 Third Party Advisory
https://blog.jetbrains.com/teamcity/2023/09/cve-2023-42793-vulnerability-post-mortem/ Vendor Advisory
https://www.jetbrains.com/privacy-security/issues-fixed/ Vendor Advisory
https://www.rapid7.com/blog/post/2023/09/25/etr-cve-2023-42793-critical-authentication-bypass-in-jetbrains-teamcity-ci-c Broken LinkThird Party Advisory
https://www.securityweek.com/recently-patched-teamcity-vulnerability-exploited-to-hack-servers/ Press/Media Coverage
https://www.sonarsource.com/blog/teamcity-vulnerability/ ExploitThird Party Advisory
http://packetstormsecurity.com/files/174860/JetBrains-TeamCity-Unauthenticated-Remote-Code-Execution.html ExploitThird Party AdvisoryVDB Entry
https://attackerkb.com/topics/1XEEEkGHzt/cve-2023-42793 Third Party Advisory
https://blog.jetbrains.com/teamcity/2023/09/cve-2023-42793-vulnerability-post-mortem/ Vendor Advisory
https://www.jetbrains.com/privacy-security/issues-fixed/ Vendor Advisory
https://www.rapid7.com/blog/post/2023/09/25/etr-cve-2023-42793-critical-authentication-bypass-in-jetbrains-teamcity-ci-c Broken LinkThird Party Advisory
https://www.securityweek.com/recently-patched-teamcity-vulnerability-exploited-to-hack-servers/ Press/Media Coverage
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-42793 US Government Resource

Track CVE-2023-42793 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2024-27198JetBrains TeamCity authentication bypass allows admin actionsJetBrains TeamCity before 2023.11.4 contains an authentication bypass via an alternate path (CWE-288), letting an unauthenticated attacker reach func…KEVEPSS 100%analysed7.3CVE-2024-27199JetBrains TeamCity path traversal enables limited admin actionsJetBrains TeamCity before 2023.11.4 is vulnerable to relative path traversal that lets an unauthenticated remote party perform limited administrative…KEVEPSS 100%analysed10.0CVE-2026-65906Jetbrains teamcity code injection vulnerabilityIn JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possibleEPSS 0.66%9.8CVE-2025-54530Jetbrains teamcity incorrect default permissions vulnerabilityIn JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissionsEPSS 0.18%9.8CVE-2025-46433Jetbrains teamcity relative path traversal vulnerabilityIn JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possibleEPSS 0.55%9.8CVE-2024-41827Jetbrains teamcity insufficient session expiration vulnerabilityIn JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expirationEPSS 0.40%9.8CVE-2024-36470Jetbrains teamcity authentication bypass via alternate path vulnerabilityIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge casesEPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2023-42793), CISA KEV, FIRST EPSS (scores of 2026-09-20). This page is refreshed as NVD updates the record.