Hackers are exploiting a critical authentication-bypass vulnerability, CVE-2026-82329, in JFrog Artifactory to forge tokens that provide administrative access.
The flaw affects the default configuration of self-managed Artifactory instances, which organizations use to store, organize, secure, and distribute software packages. An unauthenticated attacker with network access could exploit it to gain administrative permissions.
Researchers at offensive security company watchTowr observed attackers “minting themselves admin tokens.” Details remain limited, and JFrog’s advisory provides few technical specifics beyond confirming exploitability in the default configuration.
Administrative access can allow attackers to enumerate users, groups, and federated topologies, read artifacts, change security configurations, and poison existing packages. Because build and deployment systems automatically pull trusted binaries, modified artifacts could potentially lead to malicious code execution downstream.
JFrog addressed the issue on August 28 in Artifactory versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20. The vendor said JFrog Cloud environments were already protected. Existing access tokens have separate expiration and revocation mechanisms, so upgrading the binary does not by itself invalidate previously issued tokens.
The extent of the compromise, victim count, telemetry, and indicators of compromise remain unclear. BleepingComputer said it contacted JFrog but had not received a response.
Comments
0No comments yet. Be the first to comment.