Critical Analysis: CVE-2024-27199 - JetBrains TeamCity Relative Path Traversal Vulnerability... — April 22, 2026
Published 22 Apr 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
Initial Discovery and Context Alright team, let’s talk about CVE-2024-27199. This one dropped on April 22, 2026, and it's a critical relative path traversal vulnerability affecting JetBrains TeamCity. Specifically, we're looking at TeamCity versions 2023.11.3 and earlier. For those of you running older releases, JetBrains has provided patches for 2023.11.4 and 2023.05.5, along with an advisory for those on even older, unsupported tracks to upgrade immediately. What makes this particularly nasty is its impact on a widely adopted CI/CD platform. TeamCity is often the beating heart of an organization's development pipeline, directly connected to source code management, build artifacts, and deployment processes. A breach here means a potential compromise across the entire software supply chain. We’ve seen this story before with similar CI/CD vulnerabilities – adversaries target these systems