JetBrains has issued a warning about a critical security flaw in TeamCity On-Premises, its self-hosted continuous integration and delivery platform. The company says the weakness allows an authentication bypass, and that attackers could use it to achieve remote code execution on affected systems.

That combination makes the issue particularly severe. When a bug lets an unauthenticated attacker reach remote code execution, exposed servers can become a high-value target because build and automation tools often sit close to source code, deployment pipelines, and other sensitive internal resources.

JetBrains has indicated the vulnerability is being tracked under a CVE entry and has tied the problem specifically to TeamCity On-Premises deployments. For organizations running their own TeamCity servers, the alert signals an urgent need to review exposure and confirm whether their instances are affected.

Teams using TeamCity On-Premises should prioritize the vendor’s security guidance and apply any recommended updates or mitigations as quickly as possible. Until systems are reviewed and secured, the flaw represents a serious risk for development environments that rely on the platform.