Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

JetBrains TeamCity Relative Path Traversal (CVE-2024-27199)

Historical catalog analysis: CISA added this entry on April 20, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.

What the vulnerability is

CVE-2024-27199 is a relative path traversal vulnerability (CWE-23) affecting JetBrains TeamCity. This flaw could allow an attacker to perform limited administrative actions. The vulnerability has been identified as being used in known ransomware campaigns, increasing the urgency for organizations to verify their exposure and apply mitigations.

Exposure and applicability

This vulnerability applies to deployments of JetBrains TeamCity. Organizations utilizing this product—particularly those running on-premises instances—are at risk if they have not applied the vendor’s security updates. Because this flaw enables administrative actions, it represents a significant escalation path for attackers who gain initial access or target the TeamCity server directly.

Remediation priorities

Based on the reported exploitation by ransomware actors, we analyze the following priority actions for vulnerability management teams:

  1. Immediate Patching: The primary remediation is to apply vendor-supplied mitigations and updates. For those using cloud services, adherence to BOD 22-01 guidance is recommended where applicable.
  2. Asset Inventory Validation: Identify all active TeamCity instances across the environment to ensure no shadow or legacy servers remain unpatched.
  3. Decommissioning: If vendor mitigations cannot be applied or are unavailable for a specific deployment, the product should be discontinued to eliminate the attack surface.

How to validate remediation

Verification must go beyond confirming a version number. To assure that exposure has been reduced, defenders should:

  • Verify Patch Application: Confirm through system logs and package managers that the vendor’s specific security update for CVE-2024-27199 is active.
  • Configuration Audit: Review administrative access logs for any unauthorized actions performed during the window of exposure to ensure the vulnerability was not exploited prior to patching.
  • Network Exposure Check: Verify that TeamCity instances are not unnecessarily exposed to the public internet, which reduces the likelihood of external exploitation regardless of patch status.

Limits and open questions

Applying a patch reduces the likelihood of this specific path traversal being used but does not guarantee total immunity from other vulnerabilities or different attack vectors. There remains residual risk if administrative credentials were compromised during the period the system was vulnerable, as patching the software does not revoke existing unauthorized access tokens or credentials. It is currently unknown exactly which ‘limited admin actions’ are most frequently targeted in the reported ransomware campaigns.

Source and editorial note

CVE-2024-27199: JetBrains TeamCity Relative Path Traversal Vulnerability · Source date: April 20, 2026 · Retrieved August 31, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Archive date: April 23, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 13, 2026 at 00:51 UTC.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment