← Vulnerability feed

Vulnerability record · CVE-2024-23917 · published 6 February 2024

CVE-2024-23917: JetBrains TeamCity authentication bypass leads to remote code execution

Jetbrains · Teamcity

JetBrains TeamCity before 2023.11.3 contains an authentication bypass that allows an unauthenticated attacker to reach a critical function and achieve remote code execution. Because the flaw requires no credentials or user interaction and the server is network-facing, it is a serious risk to any exposed TeamCity instance.

9.8 CVSS 3.1 Critical EPSS 54% · top 1.0% CWE-288 · Authentication bypass via alternate pathCWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable RCE with a CVSS score of 9.8 and high EPSS probability makes this an urgent patching priority.

What it is

JetBrains TeamCity before 2023.11.3 contains an authentication bypass that allows an unauthenticated attacker to reach a critical function and achieve remote code execution. Because the flaw requires no credentials or user interaction and the server is network-facing, it is a serious risk to any exposed TeamCity instance.

Impact

An attacker gains unauthenticated remote code execution on the TeamCity server, which can lead to full compromise of the CI/CD environment, including build secrets, source code and connected systems.

Attack surface

Reachable over the network via the TeamCity web interface (CVSS vector AV:N/PR:N/UI:N), so no authentication and no user interaction are required. The record does not specify the exact endpoint or request path involved.

Exploitation

The record does not list this CVE in CISA KEV and provides no exploit reference tags, but EPSS is high at 0.5373 (99th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade TeamCity to 2023.11.3 or later as the primary fix.
  • If immediate upgrade is not possible, restrict network access to the TeamCity server to trusted networks and remove direct internet exposure.
  • Review and rotate credentials, tokens and secrets stored in or reachable from TeamCity, since RCE may expose them.
  • Audit TeamCity server logs and build history for unauthorized changes or unexpected build steps.
  • Monitor vendor advisories for further guidance on affected versions and any interim workarounds.

Detection

  • Review TeamCity server and web access logs for unauthenticated requests to administrative or build-triggering endpoints, especially from unfamiliar source IPs.
  • Alert on unexpected creation or modification of build configurations, projects, users or plugins.
  • Monitor for suspicious child processes spawned by the TeamCity server process (for example shells or download utilities).
  • Watch for outbound connections from the TeamCity host to unknown external addresses that could indicate post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-23917 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2024-27198JetBrains TeamCity authentication bypass allows admin actionsJetBrains TeamCity before 2023.11.4 contains an authentication bypass via an alternate path (CWE-288), letting an unauthenticated attacker reach func…KEVEPSS 100%analysed9.8CVE-2023-42793JetBrains TeamCity authentication bypass leads to remote code executionJetBrains TeamCity before 2023.05.4 contains an authentication bypass via an alternate path, classified as CWE-288 and CWE-306, that allows an unauth…KEVEPSS 100%analysed7.3CVE-2024-27199JetBrains TeamCity path traversal enables limited admin actionsJetBrains TeamCity before 2023.11.4 is vulnerable to relative path traversal that lets an unauthenticated remote party perform limited administrative…KEVEPSS 100%analysed10.0CVE-2026-65906Jetbrains teamcity code injection vulnerabilityIn JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possibleEPSS 0.66%9.8CVE-2025-54530Jetbrains teamcity incorrect default permissions vulnerabilityIn JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissionsEPSS 0.18%9.8CVE-2025-46433Jetbrains teamcity relative path traversal vulnerabilityIn JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possibleEPSS 0.55%9.8CVE-2024-41827Jetbrains teamcity insufficient session expiration vulnerabilityIn JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expirationEPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2024-23917), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.