← Vulnerability feed

Vulnerability record · CVE-2024-27199 · published 4 March 2024

CVE-2024-27199: JetBrains TeamCity path traversal enables limited admin actions

Jetbrains · Teamcity

JetBrains TeamCity before 2023.11.4 is vulnerable to relative path traversal that lets an unauthenticated remote party perform limited administrative actions. Because TeamCity is a CI/CD server, compromise can expose build pipelines and the credentials and artifacts they handle.

7.3 CVSS 3.1 High CISA KEV since 20 Apr 2026 Known ransomware use EPSS 100% · top 0.1% CWE-23 · Relative path traversalCWE-22 · Path traversal
7.3CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityIt is in CISA KEV with known ransomware use, has an EPSS probability near 1.0, a public exploit reference, and unauthenticated network reachability.

What it is

JetBrains TeamCity before 2023.11.4 is vulnerable to relative path traversal that lets an unauthenticated remote party perform limited administrative actions. Because TeamCity is a CI/CD server, compromise can expose build pipelines and the credentials and artifacts they handle.

Impact

An attacker gains the ability to carry out a limited set of administrative actions without authenticating, which can be used to weaken the server's configuration or as a foothold for further attacks. The CVSS impact ratings are all Low, so the direct damage per action is constrained, but the server's role makes follow-on risk significant.

Attack surface

Reachable over the network via HTTP against the TeamCity server; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to attempt the traversal.

Exploitation

CISA added this to KEV with a due date of 2026-05-04 and flags known ransomware campaign use, and EPSS is near 1.0 (0.99991, 99.986th percentile). A public exploit reference exists, and press coverage describes mass exploitation of TeamCity.

What to do

  • Upgrade TeamCity to 2023.11.4 or later, or apply the vendor's mitigation guidance if upgrading is not immediately possible.
  • If the server is internet-facing and cannot be patched promptly, restrict access to trusted networks or take it offline per BOD 22-01 guidance.
  • Rotate credentials, tokens and secrets stored in or used by TeamCity, and review build configurations for unauthorized changes.
  • Audit TeamCity accounts and remove any rogue or unexpected administrative accounts.
  • Monitor vendor advisories for follow-up fixes, since this CVE is linked to the same TeamCity exploitation wave as CVE-2024-27198.

Detection

  • Review TeamCity server logs for requests containing path traversal sequences (../, encoded variants) against administrative endpoints.
  • Alert on creation of new administrative accounts or unexpected changes to server settings outside normal change windows.
  • Hunt for outbound connections or new scheduled tasks/plugins on the TeamCity host that were not part of the baseline.
  • Correlate TeamCity host activity with known post-exploitation behavior, given the KEV ransomware flag.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-27199 to the Known Exploited Vulnerabilities catalog on 20 April 2026 as "JetBrains TeamCity Relative Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 4 May 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-27199 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2024-27198JetBrains TeamCity authentication bypass allows admin actionsJetBrains TeamCity before 2023.11.4 contains an authentication bypass via an alternate path (CWE-288), letting an unauthenticated attacker reach func…KEVEPSS 100%analysed9.8CVE-2023-42793JetBrains TeamCity authentication bypass leads to remote code executionJetBrains TeamCity before 2023.05.4 contains an authentication bypass via an alternate path, classified as CWE-288 and CWE-306, that allows an unauth…KEVEPSS 100%analysed10.0CVE-2026-65906Jetbrains teamcity code injection vulnerabilityIn JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possibleEPSS 0.66%9.8CVE-2025-54530Jetbrains teamcity incorrect default permissions vulnerabilityIn JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissionsEPSS 0.18%9.8CVE-2025-46433Jetbrains teamcity relative path traversal vulnerabilityIn JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possibleEPSS 0.55%9.8CVE-2024-41827Jetbrains teamcity insufficient session expiration vulnerabilityIn JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expirationEPSS 0.40%9.8CVE-2024-36470Jetbrains teamcity authentication bypass via alternate path vulnerabilityIn JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge casesEPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2024-27199), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.