Abstrakter Code als Symbol fuer eine Sicherheitsluecke

JFrog Artifactory: Critical Auth-Bypass Flaw (CVE-2026-82329) Under Active Attack

A critical authentication flaw in JFrog Artifactory is being actively exploited just days after its patch went public. Tracked as CVE-2026-82329 (CVSS 9.8), the bug sits in Artifactory’s Access component and lets unauthenticated attackers with network access obtain full administrator privileges on self-hosted instances running the default configuration. The US cybersecurity agency CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026.

Attackers forge admin tokens

JFrog shipped the fix on August 28, 2026. Shortly afterward, researchers at watchTowr observed attackers minting themselves administrator tokens on exposed servers. With those privileges, adversaries can enumerate users, groups, credentials and federated access, then deploy reverse shells and crypto miners. Because Artifactory sits at the heart of many software supply chains, storing binaries, containers, packages and AI models, the risk of follow-on compromise is severe: attackers could tamper with or steal stored artifacts and pivot into downstream systems.

Affected and patched versions

Multiple 7.x branches of self-managed installations are affected; JFrog says its Cloud offering was never vulnerable. On-premises operators must manually upgrade to one of the following fixed releases:

  • 7.111.21
  • 7.117.28
  • 7.125.20
  • 7.133.29
  • 7.146.38
  • 7.161.20

Crucially, upgrading alone does not invalidate already-issued tokens. After patching, administrators should audit existing tokens, revoke any suspicious ones and review access logs for abuse. US federal agencies must prioritize remediation under the new BOD 26-04 directive.

Sources: CISA KEV advisory (Sep 2, 2026), BleepingComputer, SecurityWeek.

Mastodon
Scroll to Top