Junglewise Threat Intelligence

CVE-2024-27199: JetBrains TeamCity relative path traversal in admin interface

CVE-2024-27199 · Severity: critical · CVSS 7.3 · Exploited in the wild · Published 2026-04-20

Technologies: Jetbrains TeamCity. Vendors: Jetbrains.

Executive brief

JetBrains TeamCity, a popular platform for automating software builds and deployments, contains a security vulnerability that allows unauthorized users to perform administrative actions. An attacker could exploit this to bypass security controls and potentially interfere with the software development pipeline. This flaw has been reported as being actively exploited in the wild, posing a significant risk to organizational software integrity and operational continuity.

Technical details

A relative path traversal vulnerability (CWE-23/CWE-22) exists in JetBrains TeamCity versions prior to 2023.11.4. The flaw allows a remote, unauthenticated attacker to bypass certain security constraints by manipulating file paths in web requests. Successful exploitation enables the attacker to perform a limited set of administrative actions on the server. This vulnerability is being actively exploited in the wild, often in conjunction with other flaws to establish persistent access or create rogue accounts. Users should update to version 2023.11.4 or later immediately.

Affected products

  • JetBrains TeamCity Before 2023.11.4

Timeline

  • 2024-03-04: disclosed: Initial NVD publication
  • 2024-03-04: advisory: Vendor advisory released by JetBrains
  • 2026-04-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats