Database/Control plane, storage & DevOps
JetBrains TeamCity: Alternative-path authentication bypass
CVSS 9.8CVE-2024-27198Control plane, storage & DevOpsKnown exploitedcurated
Impact
Alternative-path authentication bypass -> unauthenticated admin actions on the CI server
Who can reach it
Network (remote)
What to do
Control-plane: URGENT upgrade; rotate all build secrets and signing keys
References
Related entries
- JetBrains TeamCity: Deserialization in the agent polling protocolCVE-2026-63077 · JetBrains TeamCityCritical
- JetBrains TeamCity: Authentication bypass leading to remote code execution on TeamCity ServerCVE-2023-42793 · JetBrains TeamCityCritical
- Veeam Backup Enterprise Manager: Unauthenticated users can log in as any user to the Enterprise Manager web interfaceCVE-2024-29849 · Veeam Backup Enterprise ManagerCritical
- CyberPower PowerPanel platform - hardcoded database, service and cloud credentials: Hardcoded credentials usedCVE-2024-32053 · CyberPower PowerPanel platform - hardcoded database, service and cloud credentialsCritical
- CyberPower PowerPanel Enterprise prior to v2.8.3 - PDNU REST APIs: Certain utility REST APIs have no authenticationCVE-2024-32735 · CyberPower PowerPanel Enterprise prior to v2.8.3 - PDNU REST APIsCritical
- CyberPower PowerPanel business application - JWT signing key: The JWT signing key is hardcoded in the application, soCVE-2024-33625 · CyberPower PowerPanel business application - JWT signing keyCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.