Vulnerability record · CVE-2024-27199 · published 4 March 2024
CVE-2024-27199: JetBrains TeamCity path traversal enables limited admin actions
Jetbrains · Teamcity
JetBrains TeamCity before 2023.11.4 is vulnerable to relative path traversal that lets an unauthenticated remote party perform limited administrative actions. Because TeamCity is a CI/CD server, compromise can expose build pipelines and the credentials and artifacts they handle.
Description
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has an EPSS probability near 1.0, a public exploit reference, and unauthenticated network reachability.
What it is
JetBrains TeamCity before 2023.11.4 is vulnerable to relative path traversal that lets an unauthenticated remote party perform limited administrative actions. Because TeamCity is a CI/CD server, compromise can expose build pipelines and the credentials and artifacts they handle.
Impact
An attacker gains the ability to carry out a limited set of administrative actions without authenticating, which can be used to weaken the server's configuration or as a foothold for further attacks. The CVSS impact ratings are all Low, so the direct damage per action is constrained, but the server's role makes follow-on risk significant.
Attack surface
Reachable over the network via HTTP against the TeamCity server; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to attempt the traversal.
Exploitation
CISA added this to KEV with a due date of 2026-05-04 and flags known ransomware campaign use, and EPSS is near 1.0 (0.99991, 99.986th percentile). A public exploit reference exists, and press coverage describes mass exploitation of TeamCity.
What to do
- Upgrade TeamCity to 2023.11.4 or later, or apply the vendor's mitigation guidance if upgrading is not immediately possible.
- If the server is internet-facing and cannot be patched promptly, restrict access to trusted networks or take it offline per BOD 22-01 guidance.
- Rotate credentials, tokens and secrets stored in or used by TeamCity, and review build configurations for unauthorized changes.
- Audit TeamCity accounts and remove any rogue or unexpected administrative accounts.
- Monitor vendor advisories for follow-up fixes, since this CVE is linked to the same TeamCity exploitation wave as CVE-2024-27198.
Detection
- Review TeamCity server logs for requests containing path traversal sequences (../, encoded variants) against administrative endpoints.
- Alert on creation of new administrative accounts or unexpected changes to server settings outside normal change windows.
- Hunt for outbound connections or new scheduled tasks/plugins on the TeamCity host that were not part of the baseline.
- Correlate TeamCity host activity with known post-exploitation behavior, given the KEV ransomware flag.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-27199 to the Known Exploited Vulnerabilities catalog on 20 April 2026 as "JetBrains TeamCity Relative Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 4 May 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-27199 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-27199), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.