[07:00:06] === CVE-2026-63077 reproduction: TeamCity unauthenticated RCE via agent polling protocol === [07:00:06] pulling pinned images (no-op if cached) docker.io/jetbrains/teamcity-server@sha256:a435d848808ac6f9b4a8b0970e29a1b8723ed6cc28f309e6df44f334b4cb7416: Pulling from jetbrains/teamcity-server Digest: sha256:a435d848808ac6f9b4a8b0970e29a1b8723ed6cc28f309e6df44f334b4cb7416 Status: Image is up to date for jetbrains/teamcity-server@sha256:a435d848808ac6f9b4a8b0970e29a1b8723ed6cc28f309e6df44f334b4cb7416 docker.io/jetbrains/teamcity-server@sha256:a435d848808ac6f9b4a8b0970e29a1b8723ed6cc28f309e6df44f334b4cb7416 docker.io/jetbrains/teamcity-server@sha256:d3875b0d20207d161c0424c923f809109e03e2cf893cba178f28a9032ada56d8: Pulling from jetbrains/teamcity-server Digest: sha256:d3875b0d20207d161c0424c923f809109e03e2cf893cba178f28a9032ada56d8 Status: Image is up to date for jetbrains/teamcity-server@sha256:d3875b0d20207d161c0424c923f809109e03e2cf893cba178f28a9032ada56d8 docker.io/jetbrains/teamcity-server@sha256:d3875b0d20207d161c0424c923f809109e03e2cf893cba178f28a9032ada56d8 [07:00:07] vulnerable marker: /tmp/CVE_2026_63077_PWNED_8912cb8560b9 [07:00:07] fixed marker: /tmp/CVE_2026_63077_PWNED_84db3638b066 3c1e675ae5d6b39174167091be197135bc80e17c8896718109b74718f66078fe [07:00:07] [vuln] container tc-cve-2026-63077-vuln started; waiting for maintenance servlet [07:00:13] [vuln] running first-run setup wizard [07:01:10] [vuln] setup complete; verifying unauthenticated agent registration (healthcheck) [07:01:10] [vuln] healthy: /app/agents/v1/register issued a session without credentials d9e760e784b959ced3f4d20917e70de3adfe3c00763096421b76817f922f1347 [07:01:11] [fixed] container tc-cve-2026-63077-fixed started; waiting for maintenance servlet [07:01:17] [fixed] running first-run setup wizard [07:02:28] [fixed] setup complete; verifying unauthenticated agent registration (healthcheck) [07:02:29] [fixed] healthy: /app/agents/v1/register issued a session without credentials [07:02:29] [vuln attempt 1] running exploit against TeamCity 2025.11.6 [07:02:30] [vuln attempt 1] exploit script reports command execution [07:02:30] [vuln attempt 1] marker file present inside server container: -rw-r----- 1 tcuser tcuser 0 Aug 23 07:02 /tmp/CVE_2026_63077_PWNED_8912cb8560b9 uid=1000(tcuser) gid=1000(tcuser) groups=1000(tcuser) [07:02:30] [vuln attempt 2] running exploit against TeamCity 2025.11.6 [07:02:31] [vuln attempt 2] exploit script reports command execution [07:02:31] [vuln attempt 2] marker file present inside server container: -rw-r----- 1 tcuser tcuser 0 Aug 23 07:02 /tmp/CVE_2026_63077_PWNED_8912cb8560b9 uid=1000(tcuser) gid=1000(tcuser) groups=1000(tcuser) [07:02:31] [fixed attempt 1] running identical exploit against TeamCity 2025.11.7 [07:02:33] [fixed attempt 1] blocked as expected (ForbiddenClassException, no marker) [07:02:33] [fixed attempt 2] running identical exploit against TeamCity 2025.11.7 [07:02:33] [fixed attempt 2] blocked as expected (ForbiddenClassException, no marker) [07:02:33] summary: vulnerable successes=2/2, fixed blocked=2/2 vulnerable server ConversionException count: 4 [07:02:33] RESULT: CVE-2026-63077 CONFIRMED (unauthenticated RCE on 2025.11.6; 2025.11.7 blocks the payload)