๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2024-27199: JetBrains TeamCity Relative Path Traversal Vulnerability
Summary
JetBrains TeamCity has a relative path traversal vulnerability (a flaw where an attacker can access files outside their intended directory by using paths like '../../../') that could let someone perform limited admin actions without proper permission. This vulnerability is actively being exploited by attackers in real-world attacks.
Solution / Mitigation
Apply mitigations per JetBrains vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. See https://www.jetbrains.com/privacy-security/issues-fixed/ for vendor-specific details.
Vulnerability Details
EPSS: 82.5%
Yes
๐ฅ Actively Exploited
April 19, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-27199
First tracked: April 20, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%