Critical JFrog Artifactory Vulnerability Exploited Days After Disclosure

Critical JFrog Artifactory Vulnerability Exploited Days After Disclosure

watchTowr reports attackers exploiting critical CVE-2026-82329 to obtain administrator tokens from vulnerable JFrog Artifactory servers.

Listen to this article

0:00

Press play to start listening

Attackers are exploiting a critical authentication bypass in JFrog Artifactory to obtain administrator tokens, according to watchTowr Intel. Artifactory stores and distributes software packages, binaries, and build artifacts used in development pipelines. In a September 1 post on X, watchTowr said its Attacker Eye honeypot network had observed exploitation of CVE-2026-82329.

Critical Artifactory Flaw Under Attack

JFrog disclosed the vulnerability on August 28, saying that under default configuration, an unauthenticated attacker with network access could obtain administrative privileges. CVE-2026-82329 has a CVSS score of 9.8. According to watchTowr, the flaw involves JFrog Access, the component responsible for authentication and permissions. Administrative access could give an attacker broad control over an affected Artifactory server.

In a comment shared with Hackread.com, watchTowr principal threat intelligence specialist Yordan Ganchev said instances without an additional join key configured can receive a “phantom” join key, which attackers can abuse to forge access and mint administrator-level credentials.

“By September 1, threat actors were already exploiting internet-exposed systems,” Ganchev said. watchTowr’s global Attacker Eye honeypot network observed attackers minting administrator tokens and enumerating users, groups, credential sets, and federated access topologies.

“When attackers gain admin-level access to a central software supply chain system, they can do what every engineering team does best – build, ship, and distribute software fast. From there, they could tamper with build pipelines, move laterally into production systems and potentially push malicious changes downstream to customers,” Ganchev explained.

Affected Versions and Patches

According to JFrog’s security advisory, the affected self-hosted versions and fixes are:

  • 7.161.0 through 7.161.19: upgrade to 7.161.20
  • 7.146.0 through 7.146.36: upgrade to 7.146.38
  • 7.133.0 through 7.133.28: upgrade to 7.133.29
  • 7.125.0 through 7.125.19: upgrade to 7.125.20
  • 7.117.0 through 7.117.27: upgrade to 7.117.28
  • Versions earlier than 7.111.21: upgrade to 7.111.21

JFrog said affected cloud environments have already been updated with a fixed version and require no customer action.

The current vulnerability is unrelated to Artifactory weaknesses exploited by OpenAI models during internal security evaluations earlier in 2026. On June 26, the models abused a token-refresh vulnerability to gain administrator access to OpenAI’s Artifactory instance.

During the same evaluations, they also exploited a separate Artifactory flaw to obtain internet access before reaching Hugging Face systems. OpenAI later disclosed the Artifactory issues to JFrog.

watchTowr urged organizations to patch internet-exposed systems immediately. It recommended treating systems that remained exposed while vulnerable as compromised until an investigation shows otherwise, reviewing audit logs, rotating credentials, and checking connected systems for malicious changes or backdoors.

Security Experts Warn of Supply Chain Risks

In comments shared with Hackread.com, Collin Hogue-Spears, Senior Director of Solution Management at Black Duck, said:

“This is a zero-trust problem at its core. Administrative access to Artifactory reaches released artifacts that downstream systems already trust and pull automatically, which separates CVE-2026-82329 from an ordinary web-app bug.”

Hogue-Spears also warned that upgrading may leave attacker-created tokens usable. JFrog supports both expiring and non-expiring access tokens, so administrators should inspect issued tokens and revoke any that are unknown or suspicious.

James Edwards, Senior Director of Engineering at Keeper Security, said the vulnerability poses a serious software supply chain risk:

“Artifact repositories store finished code and binaries before they reach production, and an authentication bypass at this layer is a supply chain vulnerability of the first order.”

Edwards added that any vulnerable instance accessible over the network should be treated as compromised, with all administrator tokens and API keys revoked or rotated.

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts