CVE-2024-27198: JetBrains TeamCity Authentication Bypass Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-03-07. EPSS: 99.9% chance of exploitation in the next 30 days.

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

Affected products

  • JetBrains TeamCity: before 2023.11.4 (fixed in 2023.11.4)

Published 2024-03-04. Last modified 2026-06-17.