← Vulnerability feed

Vulnerability record · CVE-2024-27198 · published 4 March 2024

CVE-2024-27198: JetBrains TeamCity authentication bypass allows admin actions

Jetbrains · Teamcity

JetBrains TeamCity before 2023.11.4 contains an authentication bypass via an alternate path (CWE-288), letting an unauthenticated attacker reach functionality intended for administrators. Because TeamCity is a CI/CD server, compromise exposes build pipelines, credentials and deployment infrastructure.

9.8 CVSS 3.1 Critical CISA KEV since 7 Mar 2024 Known ransomware use EPSS 100% · top 0.1% CWE-288 · Authentication bypass via alternate path
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable authentication bypass with CVSS 9.8, KEV listing, ransomware use and near-certain exploitation probability.

What it is

JetBrains TeamCity before 2023.11.4 contains an authentication bypass via an alternate path (CWE-288), letting an unauthenticated attacker reach functionality intended for administrators. Because TeamCity is a CI/CD server, compromise exposes build pipelines, credentials and deployment infrastructure.

Impact

An attacker can perform administrative actions without valid credentials, effectively taking full control of the TeamCity server and anything it builds or deploys.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or intranet-exposed TeamCity instance below 2023.11.4 is in scope.

Exploitation

Listed in CISA KEV since 2024-03-07 with known ransomware campaign use, and EPSS 30-day probability is 0.99938 (99.97th percentile). Press coverage referenced in the record describes mass exploitation and rogue account creation.

What to do

  • Upgrade TeamCity to 2023.11.4 or later immediately; this is the only complete fix.
  • If immediate upgrade is impossible, apply JetBrains' vendor-supplied mitigation or take the server offline, per CISA's required action.
  • Restrict network access to the TeamCity web interface to trusted management networks or VPN rather than exposing it to the internet.
  • Rotate credentials, tokens and secrets stored in or reachable from TeamCity, and audit for unauthorized admin accounts.
  • Review build configurations and deployment pipelines for tampering introduced during the exposure window.

Detection

  • Audit TeamCity logs for requests to unexpected or alternate paths that precede admin-level actions from unauthenticated sessions.
  • Alert on creation of new administrator accounts or permission changes outside known change windows.
  • Monitor for anomalous build, plugin or agent configuration changes and unexpected outbound connections from the TeamCity host.
  • Hunt for known post-exploitation indicators such as rogue accounts and webshell or plugin drops on the server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-27198 to the Known Exploited Vulnerabilities catalog on 7 March 2024 as "JetBrains TeamCity Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 March 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-27198 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2023-42793JetBrains TeamCity authentication bypass leads to remote code executionJetBrains TeamCity before 2023.05.4 contains an authentication bypass via an alternate path, classified as CWE-288 and CWE-306, that allows an unauth…KEVEPSS 100%analysed7.3CVE-2024-27199JetBrains TeamCity path traversal enables limited admin actionsJetBrains TeamCity before 2023.11.4 is vulnerable to relative path traversal that lets an unauthenticated remote party perform limited administrative…KEVEPSS 100%analysed10.0CVE-2026-65906Jetbrains teamcity code injection vulnerabilityIn JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possibleEPSS 0.66%9.8CVE-2025-54530Jetbrains teamcity incorrect default permissions vulnerabilityIn JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissionsEPSS 0.18%9.8CVE-2025-46433Jetbrains teamcity relative path traversal vulnerabilityIn JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possibleEPSS 0.55%9.8CVE-2024-41827Jetbrains teamcity insufficient session expiration vulnerabilityIn JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expirationEPSS 0.40%9.8CVE-2024-36470Jetbrains teamcity authentication bypass via alternate path vulnerabilityIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge casesEPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2024-27198), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.