Back to feed

Attackers exploit JFrog Artifactory flaw to mint admin tokens days after patch

2 min
Attackers exploit JFrog Artifactory flaw to mint admin tokens days after patch

This digest was compiled by AI from multiple sources — links to the originals are below.

Threat actors are exploiting a critical authentication bypass in JFrog Artifactory, CVE-2026-82329, to mint administrator tokens and enumerate users. JFrog patched the flaw in version 7.161.20 on August 28, 2026, but exploitation began by September 1, 2026. The vulnerability affects default configurations and requires no authentication or user interaction.

Key Facts

  • CVE-2026-82329 carries a CVSS score of 9.8 and allows unauthenticated attackers to gain administrative privileges in Artifactory.
  • JFrog released the patched version 7.161.20 on August 28, 2026.
  • watchTowr confirmed that threat actors began weaponizing the flaw on September 1, 2026, to generate admin tokens and enumerate users, groups, credential sets, and federated access topologies.
  • The vulnerability affects default configurations and requires no authentication or user interaction, according to Vercel CEO Guillermo Rauch.
  • Affected versions include 7.161.0 through 7.161.19, 7.146.0 through 7.146.36, 7.133.0 through 7.133.28, 7.125.0 through 7.125.19, 7.117.0 through 7.117.27, and 7.111.4 through 7.111.21.

Exploitation Timeline

JFrog patched CVE-2026-82329 in Artifactory version 7.161.20 on August 28, 2026. watchTowr reported that threat actors began exploiting the flaw on September 1, 2026, just four days after the patch release. Yordan Ganchev, principal threat intelligence specialist at watchTowr, stated that attackers are generating admin tokens and enumerating users, groups, credential sets, and federated access topologies. Ganchev added that the transition from disclosure to real-world exploitation occurred with "uncomfortable efficiency."

Technical Impact

The vulnerability resides in JFrog Access, which issues and validates credentials. Instances without an additional join key configured receive a "phantom" join key that attackers can abuse to forge access and mint administrator-level credentials. Vercel CEO Guillermo Rauch described the flaw as an "RCE bomb" because Artifactory hosts binaries, allowing attackers to poison build pipelines and push malicious changes downstream. With admin access to a central software supply chain system, attackers could tamper with build pipelines, move laterally into production systems, and distribute malicious software to customers.

Mitigation Guidance

Organizations running self-managed JFrog Artifactory are advised to apply patches to internet-exposed systems immediately. JFrog recommends inspecting audit logs, rotating exposed credentials, and reviewing connected systems for malicious changes or backdoor access.

2 sources

Time · lag behind first