⚡ Exploit-DB.ai CRITICAL
CRITICAL

CVE-2023-42793

Published: March 18, 2026 · Source: National Vulnerability Database (NVD)

⚡ AI Threat Assessment

TeamCity auth bypass enabling complete CI/CD pipeline takeover — exploited by Lazarus Group (North Korea) and COZY BEAR (Russia) for software supply chain attacks and intellectual property theft. Update to version 2023.05.4 immediately.

📋 Official Description

TeamCity server authentication bypass allowing unauthenticated attackers to execute RCE or steal build configurations, CI tokens, and source code.

Get Real-Time CVE Alerts

Supernova subscribers receive AI-triaged CVE alerts the moment they're published — before the PoC drops.

Start Supernova — $99/mo →