Sploitus

Exploit for Deserialization of Untrusted Data in Jetbrains Teamcity

githubexploit Β· 2026-08-08

Exploit Code

README18 lines
## https://sploitus.com/exploit?id=AFCC98D3-030D-51DB-BA2D-441C735E9B6B
# teamcity-CVE-2026-63077-pcap
teamcity teamcity-CVE-2026-63077 exploitation pcap

info: 
https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/

https://www.rapid7.com/blog/post/ra-unauthenticated-rce-in-jetbrains-teamcity-cve-2026-63077/


Target: teamcity server 2025.11.3 (docker) 192.168.64.31 port 8111

Exploit: https://github.com/sfewer-r7/CVE-2026-63077 - ran from 192.168.64.32 w/ command to curl webhook.site


pcap might be useful for testing suricata rules. 

![wireshark screenshot](https://raw.githubusercontent.com/BoredHackerBlog/teamcity-CVE-2026-63077-pcap/refs/heads/main/image.png)