Vulnerability record · CVE-2024-27198 · published 4 March 2024
CVE-2024-27198: JetBrains TeamCity authentication bypass allows admin actions
Jetbrains · Teamcity
JetBrains TeamCity before 2023.11.4 contains an authentication bypass via an alternate path (CWE-288), letting an unauthenticated attacker reach functionality intended for administrators. Because TeamCity is a CI/CD server, compromise exposes build pipelines, credentials and deployment infrastructure.
Description
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable authentication bypass with CVSS 9.8, KEV listing, ransomware use and near-certain exploitation probability.
What it is
JetBrains TeamCity before 2023.11.4 contains an authentication bypass via an alternate path (CWE-288), letting an unauthenticated attacker reach functionality intended for administrators. Because TeamCity is a CI/CD server, compromise exposes build pipelines, credentials and deployment infrastructure.
Impact
An attacker can perform administrative actions without valid credentials, effectively taking full control of the TeamCity server and anything it builds or deploys.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or intranet-exposed TeamCity instance below 2023.11.4 is in scope.
Exploitation
Listed in CISA KEV since 2024-03-07 with known ransomware campaign use, and EPSS 30-day probability is 0.99938 (99.97th percentile). Press coverage referenced in the record describes mass exploitation and rogue account creation.
What to do
- Upgrade TeamCity to 2023.11.4 or later immediately; this is the only complete fix.
- If immediate upgrade is impossible, apply JetBrains' vendor-supplied mitigation or take the server offline, per CISA's required action.
- Restrict network access to the TeamCity web interface to trusted management networks or VPN rather than exposing it to the internet.
- Rotate credentials, tokens and secrets stored in or reachable from TeamCity, and audit for unauthorized admin accounts.
- Review build configurations and deployment pipelines for tampering introduced during the exposure window.
Detection
- Audit TeamCity logs for requests to unexpected or alternate paths that precede admin-level actions from unauthenticated sessions.
- Alert on creation of new administrator accounts or permission changes outside known change windows.
- Monitor for anomalous build, plugin or agent configuration changes and unexpected outbound connections from the TeamCity host.
- Hunt for known post-exploitation indicators such as rogue accounts and webshell or plugin drops on the server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-27198 to the Known Exploited Vulnerabilities catalog on 7 March 2024 as "JetBrains TeamCity Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 March 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitation-underway-rogue-accounts-thri | Press/Media CoverageThird Party Advisory |
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
| https://www.darkreading.com/cyberattacks-data-breaches/jetbrains-teamcity-mass-exploitation-underway-rogue-accounts-thri | Press/Media CoverageThird Party Advisory |
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-27198 | US Government Resource |
Track CVE-2024-27198 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-27198), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.