JFrog Artifactory Flaw Lets Unauthenticated Attackers Gain Admin Access
JFrog disclosed a critical authentication bypass vulnerability (CVE-2026-82329, CVSS 9.8) in self-hosted Artifactory instances on 28 August 2026, with active exploitation reported by 1 September. The flaw exists in the JFrog Access component and stems from a default empty join key in fresh installations, meaning no additional misconfiguration was required to be exposed. Two related vulnerabilities — CVE-2026-42018 and CVE-2026-42016 — have been chained with the bypass to obtain anonymous user tokens and escalate privileges from low-privilege access. JFrog has released patched versions across all affected maintenance branches, while cloud-hosted environments were updated automatically; self-hosted customers must upgrade manually. Because Artifactory supports non-expiring tokens, patching alone is insufficient — administrators are urged to audit and revoke unknown tokens, check for unfamiliar admin accounts, and inspect plugin directories for signs of compromise.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in